Security Advisory squirrelmail security update

Advisory: RHSA-2004:240-06
Type: Security Advisory
Severity: Important
Issued on: 2004-06-14
Last updated on: 2004-06-14
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2004-0519
CVE-2004-0520
CVE-2004-0521

Details

An updated SquirrelMail package that fixes several security vulnerabilities
is now available.

SquirrelMail is a webmail package written in PHP. Multiple
vulnerabilities have been found which affect the version of SquirrelMail
shipped with Red Hat Enterprise Linux 3.

An SQL injection flaw was found in SquirrelMail version 1.4.2 and earlier.
If SquirrelMail is configured to store user addressbooks in the database, a
remote attacker could use this flaw to execute arbitrary SQL statements.
The Common Vulnerabilities and Exposures project has assigned the name
CAN-2004-0521 to this issue.

A number of cross-site scripting (XSS) flaws in SquirrelMail version 1.4.2
and earlier could allow remote attackers to execute script as other web
users. The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CAN-2004-0519 and CAN-2004-0520 to these issues.

All users of SquirrelMail are advised to upgrade to the erratum package
containing SquirrelMail version 1.4.3a which is not vulnerable to these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
squirrelmail-1.4.3-0.e3.1.src.rpm
File outdated by:  RHSA-2009:1490
    081f186411150fea88f0533185f7bafb
 
IA-32:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
x86_64:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
squirrelmail-1.4.3-0.e3.1.src.rpm
File outdated by:  RHSA-2009:1490
    081f186411150fea88f0533185f7bafb
 
IA-32:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
IA-64:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
PPC:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
s390:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
s390x:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
x86_64:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
squirrelmail-1.4.3-0.e3.1.src.rpm
File outdated by:  RHSA-2009:1490
    081f186411150fea88f0533185f7bafb
 
IA-32:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
IA-64:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
x86_64:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
squirrelmail-1.4.3-0.e3.1.src.rpm
File outdated by:  RHSA-2009:1490
    081f186411150fea88f0533185f7bafb
 
IA-32:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
IA-64:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
x86_64:
squirrelmail-1.4.3-0.e3.1.noarch.rpm
File outdated by:  RHSA-2009:1490
    fe78cd5ef4feb1aec5923dd2e6b3a5f9
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

122512 - CAN-2004-0519/20/21 XSS and SQL issues in Squirrelmail


References


Keywords

cross-site, injection, scripting, sql, XSS


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/