MEDIUM
security flaw
Published Aug 11, 2006
6.4
MEDIUMCVSS 2.0
EPSS 9.98%
Description
Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users.
Affected products
No data.
OR
- 1.4.0
- 1.4.1
- 1.4.2
- 1.4.3
- 1.4.3_r3
- 1.4.3_rc1
- 1.4.3a
- 1.4.4
- 1.4.4_rc1
- 1.4.5
- 1.4.6
- 1.4.6_rc1
- 1.4.7
- 1.4_rc1
- 1.44
No data.
Red Hat Enterprise Linux 3
squirrelmail-0:1.4.8-2.el3
Fixed · RHSA-2006:0668
Red Hat Enterprise Linux 4
squirrelmail-0:1.4.8-2.el4
Fixed · RHSA-2006:0668
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | squirrelmail-0:1.4.8-2.el3 | Fixed | RHSA-2006:0668 |
| Red Hat Enterprise Linux 4 | squirrelmail-0:1.4.8-2.el4 | Fixed | RHSA-2006:0668 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (33)
- ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc vendor-advisoryx_refsource_SGI
- http://attrition.org/pipermail/vim/2006-August/000970.html mailing-listx_refsource_VIM
- http://docs.info.apple.com/article.html?artnum=306172 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html vendor-advisoryx_refsource_APPLE
- http://marc.info/?l=full-disclosure&m=115532449024178&w=2 mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/21354 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/21444 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21586 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22080 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22104 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22487 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26235 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1016689 vdb-entryx_refsource_SECTRACK
- http://www.debian.org/security/2006/dsa-1154 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:147 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_23_sr.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/27917 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0668.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/442980/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/442993/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/19486 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/25159 vdb-entryx_refsource_BID
- http://www.squirrelmail.org/patches/sqm1.4.7-expired-post-fix-full.patch x_refsource_MISCPatch
- http://www.squirrelmail.org/security/issue/2006-08-11 x_refsource_CONFIRMPatch
- http://www.vupen.com/english/advisories/2006/3271 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/2732 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-4019 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618173 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28365 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-577 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-4019
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11533 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-4019
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 11, 2006
Updated Aug 7, 2024
Reserved Aug 8, 2006
Link CVE-2006-4019
CISA Vulnrichment
Updated n/a