[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2009:0057 -- centos 5 x86_64 squirrelmail

ID: oval:org.secpod.oval:def:201964Date: (C)2012-01-31   (M)2023-11-09
Class: PATCHFamily: unix




SquirrelMail is an easy-to-configure, standards-based, webmail package written in PHP. It includes built-in PHP support for the IMAP and SMTP protocols, and pure HTML 4.0 page-rendering for maximum browser-compatibility, strong MIME support, address books, and folder manipulation. The Red Hat SquirrelMail packages provided by the RHSA-2009:0010 advisory introduced a session handling flaw. Users who logged back into SquirrelMail without restarting their web browsers were assigned fixed session identifiers. A remote attacker could make use of that flaw to hijack user sessions. SquirrelMail users should upgrade to this updated package, which contains a patch to correct this issue. As well, all users who used affected versions of SquirrelMail should review their preferences.

Platform:
CentOS 5
Product:
squirrelmail
Reference:
CESA-2009:0057
CVE-2009-0030
CVE-2009-1580
CVE    2
CVE-2009-0030
CVE-2009-1580
CPE    2
cpe:/a:squirrelmail:squirrelmail
cpe:/o:centos:centos:5

© SecPod Technologies