![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.56394 |
Category: | Debian Local Security Checks |
Title: | Debian: Security Advisory (DSA-988-1) |
Summary: | The remote host is missing an update for the Debian 'squirrelmail' package(s) announced via the DSA-988-1 advisory. |
Description: | Summary: The remote host is missing an update for the Debian 'squirrelmail' package(s) announced via the DSA-988-1 advisory. Vulnerability Insight: Several vulnerabilities have been discovered in Squirrelmail, a commonly used webmail system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-0188 Martijn Brinkers and Ben Maurer found a flaw in webmail.php that allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter. CVE-2006-0195 Martijn Brinkers and Scott Hughes discovered an interpretation conflict in the MagicHTML filter that allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) '/*' and '*/' comments, or (2) slashes inside the 'url' keyword, which is processed by some web browsers including Internet Explorer. CVE-2006-0377 Vicente Aguilera of Internet Security Auditors, S.L. discovered a CRLF injection vulnerability, which allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka 'IMAP injection.' There's no known way to exploit this yet. For the old stable distribution (woody) these problems have been fixed in version 1.2.6-5. For the stable distribution (sarge) these problems have been fixed in version 2:1.4.4-8. For the unstable distribution (sid) these problems have been fixed in version 2:1.4.6-1. We recommend that you upgrade your squirrelmail package. Affected Software/OS: 'squirrelmail' package(s) on Debian 3.0, Debian 3.1. Solution: Please install the updated package(s). CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2006-0188 BugTraq ID: 16756 http://www.securityfocus.com/bid/16756 Debian Security Information: DSA-988 (Google Search) http://www.debian.org/security/2006/dsa-988 http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml http://www.mandriva.com/security/advisories?name=MDKSA-2006:049 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10419 http://www.redhat.com/support/errata/RHSA-2006-0283.html http://securitytracker.com/id?1015662 http://secunia.com/advisories/18985 http://secunia.com/advisories/19130 http://secunia.com/advisories/19131 http://secunia.com/advisories/19176 http://secunia.com/advisories/19205 http://secunia.com/advisories/19960 http://secunia.com/advisories/20210 SGI Security Advisory: 20060501-01-U ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc SuSE Security Announcement: SUSE-SR:2006:005 (Google Search) http://www.novell.com/linux/security/advisories/2006_05_sr.html http://www.vupen.com/english/advisories/2006/0689 XForce ISS Database: squirrelmail-webmail-xss(24847) https://exchange.xforce.ibmcloud.com/vulnerabilities/24847 Common Vulnerability Exposure (CVE) ID: CVE-2006-0195 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9548 XForce ISS Database: squirrelmail-magichtml-xss(24848) https://exchange.xforce.ibmcloud.com/vulnerabilities/24848 Common Vulnerability Exposure (CVE) ID: CVE-2006-0377 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11470 XForce ISS Database: squirrelmail-mailbox-imap-injection(24849) https://exchange.xforce.ibmcloud.com/vulnerabilities/24849 |
Copyright | Copyright (C) 2008 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |