{"id":"DSA-662-2","summary":"squirrelmail - several","details":"\nAndrew Archibald discovered that the last update to squirrelmail which\nwas intended to fix several problems caused a regression which got\nexposed when the user hits a session timeout.  For completeness below\nis the original advisory text:\n\n\n\n\u003e \n\u003e Several vulnerabilities have been discovered in Squirrelmail, a\n\u003e commonly used webmail system. The Common Vulnerabilities and\n\u003e Exposures project identifies the following problems:\n\u003e \n\u003e \n\u003e * [CAN-2005-0104](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0104)\n\u003e Upstream developers noticed that an unsanitised variable could\n\u003e  lead to cross site scripting.\n\u003e \n\u003e * [CAN-2005-0152](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0152)\n\u003e Grant Hollingworth discovered that under certain circumstances URL\n\u003e  manipulation could lead to the execution of arbitrary code with\n\u003e  the privileges of www-data. This problem only exists in version\n\u003e  1.2.6 of Squirrelmail.\n\u003e \n\u003e \n\u003e \n\n\nFor the stable distribution (woody) these problems have been fixed in\nversion 1.2.6-3.\n\n\nFor the unstable distribution (sid) the problem that affects unstable\nhas been fixed in version 1.4.4-1.\n\n\nWe recommend that you upgrade your squirrelmail package.\n\n\n","modified":"2022-07-04T02:01:11.193292Z","published":"2005-03-14T00:00:00Z","withdrawn":"2024-05-15T05:36:14.063686Z","schema_version":"1.7.3"}