![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.62821 |
Category: | Fedora Local Security Checks |
Title: | Fedora Core 10 FEDORA-2008-10748 (squirrelmail) |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing an update to squirrelmail announced via advisory FEDORA-2008-10748. SquirrelMail is a basic webmail package written in PHP4. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no Javascript) for maximum compatibility across browsers. It has very few requirements and is very easy to configure and install. Update Information: update to 1.4.7 fixes: malformed HTML mail message script insertion ChangeLog: * Thu Dec 4 2008 Michal Hlavinka - 1.4.17-2 - add missing locales * Thu Dec 4 2008 Michal Hlavinka - 1.4.17-1 - update to 1.4.17 (fixes CVE-2008-2379) References: [ 1 ] Bug #473877 - CVE-2008-2379 squirrelmail: XSS issue caused by an insufficient html mail sanitation https://bugzilla.redhat.com/show_bug.cgi?id=473877 Solution: Apply the appropriate updates. This update can be installed with the yum update program. Use su -c 'yum update squirrelmail' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/. https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2008-10748 Risk factor : Medium CVSS Score: 4.3 |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-2379 http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html BugTraq ID: 32603 http://www.securityfocus.com/bid/32603 Debian Security Information: DSA-1682 (Google Search) http://www.debian.org/security/2008/dsa-1682 https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00223.html https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00449.html http://security-net.biz/wsw/index.php?p=254&n=190 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9764 http://secunia.com/advisories/32143 http://secunia.com/advisories/33054 http://secunia.com/advisories/33071 http://secunia.com/advisories/33937 SuSE Security Announcement: SUSE-SR:2008:027 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html http://www.vupen.com/english/advisories/2008/3332 XForce ISS Database: squirrelmail-html-xss(47024) https://exchange.xforce.ibmcloud.com/vulnerabilities/47024 |
Copyright | Copyright (c) 2008 E-Soft Inc. http://www.securityspace.com |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |