MGASA-2017-0121
Dashboard / Vulnerabilities / MGASA-2017-0121
Summary: Updated squirrelmail packages fix security vulnerability
Details: Squirrelmail version 1.4.22 (and probably prior) is vulnerable to a remote code execution vulnerability because it fails to sanitize a string before passing it to a popen call. It's possible to exploit this vulnerability to execute arbitrary shell commands on the remote server (CVE-2017-7692).
References: https://advisories.mageia.org/MGASA-2017-0121.html, https://bugs.mageia.org/show_bug.cgi?id=20703, http://openwall.com/lists/oss-security/2017/04/19/6
Affected packages
Package
Name: squirrelmail
Purl: pkg:rpm/mageia/squirrelmail?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.4.22-12.2.mga5
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
