squirrelmail-1.4.8-5.3AXS3
エラータID: AXSA:2009-17:02
SquirrelMail is a standards-based webmail package written in PHP4. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no Javascript) for maximum compatibility across browsers. It has very few requirements and is very easy to configure and install. SquirrelMail has all the functionality you would want from an email client, including strong MIME support, address books, and folder manipulation.
Fixed bugs:
CVE-2009-0030
A patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.
Update packages.
A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.
N/A
SRPMS
- squirrelmail-1.4.8-5.3AXS3.src.rpm
MD5: 60c0e60fa727171beab9e941c06030c9
SHA-256: 580ce7e24d87bc0d7080c5b210a80ffd3859f4cb03c2698b8d74101a3efcad3e
Size: 3.00 MB
Asianux Server 3 for x86
- squirrelmail-1.4.8-5.3AXS3.noarch.rpm
MD5: efab2a55e220fafc1b73e85cd69b020a
SHA-256: 5bc1ca4ccef4e7c127823e3551893c1afaebbd12e3679b193e38a4ed3b5c0f4e
Size: 4.32 MB
Asianux Server 3 for x86_64
- squirrelmail-1.4.8-5.3AXS3.noarch.rpm
MD5: 3cbb1f5f0caea59654803473f95282f4
SHA-256: 92a1bcd876e0db7ef7bfe386af4b72d38cdbd923a2bca9ba70ffc9c80fa3137f
Size: 4.31 MB