Title: Squirrelmail G/PGP Encryption Plugin Remote Command Execution Vulnerability
Severity: HIGH
Description:
Squirrelmail is a freely available, open source webmail package. It is available for the Unix and Linux platforms.
A problem in the handling of some types of input passed to the Squirrelmail G/PGP Plugin has been discovered. This issue may make it possible for a remote user to gain unauthorized access to a system hosting the vulnerable application.
The problem is in the checking of input. When an e-mail is sent to a user through a Squirrelmail implementation which uses the G/PGP plugin, the program does not sufficiently sanitize user input. Because of this, an attacker can place shell commands in the To: line of an e-mail sent through Squirrelmail which, when encrypted with the G/PGP plugin, forces the execution of the commands supplied by the attacker.
It should be noted that this issue is limited by the permissions of the web server process.
**December 26, 2003 - The vendor has reported that Squirrelmail version 1.4.2 is not vulnerable to this issue, however, Squirrelmail version 1.4.0 with GPG version 1.2 is reportedly vulnerable. This information cannot be completely verified at the moment; therefore this BID will be updated as more information becomes available.
Affected Products:
- SquirrelMail G/PGP Encryption Plugin 1.0.0
- SquirrelMail G/PGP Encryption Plugin 1.0.1
- SquirrelMail G/PGP Encryption Plugin 1.0.2
- SquirrelMail G/PGP Encryption Plugin 1.1.0
- SquirrelMail SquirrelMail 1.0.4
- SquirrelMail SquirrelMail 1.0.5
- SquirrelMail SquirrelMail 1.2.0 .0
- SquirrelMail SquirrelMail 1.2.1
- SquirrelMail SquirrelMail 1.2.10
- SquirrelMail SquirrelMail 1.2.11
- SquirrelMail SquirrelMail 1.2.2
- SquirrelMail SquirrelMail 1.2.3
- SquirrelMail SquirrelMail 1.2.4
- SquirrelMail SquirrelMail 1.2.5
- SquirrelMail SquirrelMail 1.2.6
- SquirrelMail SquirrelMail 1.2.7
- SquirrelMail SquirrelMail 1.2.8
- SquirrelMail SquirrelMail 1.2.9
- SquirrelMail SquirrelMail 1.4.0
- SquirrelMail SquirrelMail 1.4.1
- SquirrelMail SquirrelMail 1.4.2
References:
- Squirrelmail: Plugin Page
- XMB: XMB Homepage
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.