Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 135921 - mail-client/squirrelmail <= 1.4.6 - Exposure of sensitive information
Summary: mail-client/squirrelmail <= 1.4.6 - Exposure of sensitive information
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/20406/
Whiteboard: B4 [noglsa] DerCorny
Keywords:
: 135922 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-06-07 07:15 UTC by Timo Boettcher
Modified: 2006-06-19 09:25 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Timo Boettcher 2006-06-07 07:15:07 UTC
http://www.squirrelmail.org/changelog.php
the 1.4.7 release of squirrelmail fixes several bugs, at least on of them is considered security-relevant.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2006-06-07 07:15:35 UTC
*** Bug 135922 has been marked as a duplicate of this bug. ***
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2006-06-07 07:23:37 UTC
http://www.squirrelmail.org/security/issue/2006-06-01
http://secunia.com/advisories/20406/

Description:
Junker Broke has reported a vulnerability in Squirrelmail, which can be exploited by malicious people to disclose certain sensitive information.

Input passed to the "plugins[]" parameter in functions/plugin.php is not properly sanitised before being used to include files. This can be exploited to include arbitrary files from local resources.

Successful exploitation requires that "register_globals" is enabled and "magic_quotes_gpc" is disabled.

The vulnerability has been reported in version 1.4.6 and prior.

Solution:
Apply patch (see vendor advisory).

Provided and/or discovered by:
Junker Broke

Original Advisory:
http://www.squirrelmail.org/security/issue/2006-06-01
Comment 3 Stefan Cornelius (RETIRED) gentoo-dev 2006-06-07 07:36:37 UTC
eradicator please provide fixed ebuilds or tell us if 1.5.X is ready to go stable, thanks
Comment 4 Stefan Cornelius (RETIRED) gentoo-dev 2006-06-13 03:18:52 UTC
eradicator doesnt respond, someone from net-mail please bump and/or comment
Comment 5 Tuan Van (RETIRED) gentoo-dev 2006-06-13 13:27:51 UTC
committed squirrelmail-1.4.6-r3 with the mentioned patch above.
Comment 6 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-14 03:47:31 UTC
Arches please test and mark stable.
Comment 7 Chris Gianelloni (RETIRED) gentoo-dev 2006-06-14 06:04:22 UTC
x86 done... thanks to Ticho for testing...
Comment 8 Tobias Scherbaum (RETIRED) gentoo-dev 2006-06-14 11:00:58 UTC
ppc stable
Comment 9 Jon Hood (RETIRED) gentoo-dev 2006-06-14 11:09:39 UTC
amd64 stable
Comment 10 Thorsten Zantis 2006-06-14 11:34:03 UTC
 * Applying sec-135921.patch ...

 * Failed Patch: sec-135921.patch !
 *  ( /usr/portage/mail-client/squirrelmail/files/sec-135921.patch )
 *
 * Include in your bugreport the contents of:
 *
 *   /var/tmp/portage/squirrelmail-1.4.6-r3/temp/sec-135921.patch-2795.out


Bugzilla gives me an error when trying to attach above file, see it at http://pastebin.com/709062
Comment 11 Tuan Van (RETIRED) gentoo-dev 2006-06-14 12:02:44 UTC
(In reply to comment #10)
>  * Applying sec-135921.patch ...
> 
>  * Failed Patch: sec-135921.patch !
>  *  ( /usr/portage/mail-client/squirrelmail/files/sec-135921.patch )
>  *
>  * Include in your bugreport the contents of:
>  *
>  *   /var/tmp/portage/squirrelmail-1.4.6-r3/temp/sec-135921.patch-2795.out
> 
> 
> Bugzilla gives me an error when trying to attach above file, see it at
> http://pastebin.com/709062
> 

Thorsten,
please comment and post your `emerge --info` in bug #136773
Comment 12 Jason Wever (RETIRED) gentoo-dev 2006-06-14 17:19:57 UTC
Stable on SPARC.
Comment 13 Thomas Cort (RETIRED) gentoo-dev 2006-06-15 18:05:45 UTC
alpha stable.
Comment 14 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-19 03:25:16 UTC
time to vote.

i vote a full no : who has "register_globals=on" nowadays ? I guess they even don't read any security advisory...
Comment 15 Wolf Giesen (RETIRED) gentoo-dev 2006-06-19 05:05:42 UTC
One more NO. No excuse. We're not the Gentoo Security Education Project...
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-19 09:25:18 UTC
One more NO and closing. Feel free to reopen if you disagree.