Back

MEDIUM

Squirrelmail compromise

Published Dec 14, 2007

Description

SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, which allows remote attackers to execute arbitrary code.

Affected products

Remediation

Red Hat statement

The versions of SquirrelMail packages shipped in Red Hat Enterprise Linux 3, 4, and 5 were not affected by this issue. In addition, the Red Hat Product Security have verified that the malicious code is not part of released Red Hat Enterprise Linux squirrelmail packages.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 14, 2007
Updated Aug 7, 2024
Reserved Dec 14, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Dec 13, 2007