Secunia Logo  
 
Debian update for squirrelmail
Secunia Advisory: SA19176
Release Date: 2006-03-09
Popularity: 6,661 views

Critical:
Less critical
Impact: Cross Site Scripting
Manipulation of data
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux 3.1
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-0188
CVE-2006-0195
CVE-2006-0377


Description:
Debian has issued an update for squirrelmail. This fixes some vulnerabilities, which can be exploited by malicious users to manipulate certain information and by malicious people to conduct cross-site scripting attacks.

For more information:
SA18985

Solution:
Apply updated packages.

-- Debian GNU/Linux 3.0 alias woody --

Source archives:

http://security.debian.org/pool/updat...squirrelmail/squirrelmail_1.2.6-5.dsc
Size/MD5 checksum: 582 07fe8ca983ec4bf8a3355a91c79c9d78
http://security.debian.org/pool/updat...rrelmail/squirrelmail_1.2.6-5.diff.gz
Size/MD5 checksum: 24884 a65726611c8f71274582b353e309a9a1
http://security.debian.org/pool/updat...elmail/squirrelmail_1.2.6.orig.tar.gz
Size/MD5 checksum: 1856087 be9e6be1de8d3dd818185d596b41a7f1

Architecture independent components:

http://security.debian.org/pool/updat...rrelmail/squirrelmail_1.2.6-5_all.deb
Size/MD5 checksum: 1841716 1d246bc2ffe2323e2503202bfc147d9c


-- Debian GNU/Linux 3.1 alias sarge --

Source archives:

http://security.debian.org/pool/updat...squirrelmail/squirrelmail_1.4.4-8.dsc
Size/MD5 checksum: 678 140546ee9c0534419ddcaf3c7e632110
http://security.debian.org/pool/updat...rrelmail/squirrelmail_1.4.4-8.diff.gz
Size/MD5 checksum: 24654 15ddd8f4db234006a1ac290087640dfc
http://security.debian.org/pool/updat...elmail/squirrelmail_1.4.4.orig.tar.gz
Size/MD5 checksum: 575871 f50548b6f4f24d28afb5e6048977f4da

Architecture independent components:

http://security.debian.org/pool/updat...rrelmail/squirrelmail_1.4.4-8_all.deb
Size/MD5 checksum: 570472 2087dcea05cd5e1c4033f15cf120761a

-- Debian GNU/Linux unstable alias sid --

Fixed in version 2:1.4.6-1.

Original Advisory:
http://www.debian.org/security/2006/dsa-988

Other References:
SA18985:
http://secunia.com/advisories/18985/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Drupal Project Module File Upload and Cross-Site Scripting // 64 views
2. SAP GUI TabOne ActiveX Control Caption List Buffer Overflow // 55 views
3. SmbFTPD Long Command Processing Vulnerability // 48 views
4. Symantec Mail Security for SMTP Response Handling Denial of Service // 39 views
5. Drupal Project Issue Tracking Module Multiple Vulnerabilities // 38 views
6. Internet Explorer Data Binding Memory Corruption Vulnerability // 37 views
7. PHP-Fusion Members CV Module "sortby" SQL Injection Vulnerability // 36 views
8. Cisco Global Site Selector DNS Request Denial of Service // 36 views
9. Lasso OpenSSL "DSA_verify()" Spoofing Vulnerability // 35 views
10. FreeBSD update for openssl // 31 views