Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 90585 - mail-mta/courier: sqwebmail HTTP splitting attack ?
Summary: mail-mta/courier: sqwebmail HTTP splitting attack ?
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Auditing (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://seclists.org/lists/bugtraq/200...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-04-27 00:57 UTC by Thierry Carrez (RETIRED)
Modified: 2005-07-16 01:55 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2005-04-27 00:57:05 UTC
From BugTraq:

==========================================
Hackers Center Security Group (http://www.hackerscenter.com/)        
Zinho's Security Advisory         

Desc: Http Splitting leads to email account stealing 
Product: SQWebmail 
Risk: High 

A dangerous http splitting attack can be taken against mailboxes that  use Sqwebmail as web mail interface. Anyone can send a malformed  link in the email body and stealing session cookie and passwords. 

Proof of concept:  
///  
sqwebmail?redirect=%0d%0a%0d%0a[INJECT SCRIPT] 
///  

Vendor should patch this issue soon as anyone can attack a user  directly. 

Author:         
Zinho is webmaster and founder of http://www.hackerscenter.com ,      
Security research   portal       
Secure Web Hosting Companies Reviewed:      
http://www.securityforge.com/web-hosting/secure-web-hosting.asp      

zinho-no-spam @ hackerscenter.com
===============================================
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-27 07:36:35 UTC
Scott please advise.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-02 22:48:49 UTC
swtaylor seems to be MIA, ticho could you look into it?
Comment 3 Andrej Kacian (RETIRED) gentoo-dev 2005-05-03 06:51:43 UTC
Um, I can't find sqwebmail in portage. I have recently closed one ancient sqwebmail bug because of this too.

I couldn't find sqwebmail in cvs attic as well, I am at a loss to find out what happened to that package.
Comment 4 Andrej Kacian (RETIRED) gentoo-dev 2005-05-03 07:09:08 UTC
I'm afraid I can't do much until upstream provides a solution (be it patch or new version). Entire courier, as well as sqwebmail is completely alien to me.

As soon as upstream provides a solution, I can try to apply it if swtailor will still be gone.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-11 07:35:08 UTC
Ticho any news on this one?
Comment 6 Andrej Kacian (RETIRED) gentoo-dev 2005-05-11 10:47:33 UTC
I'm afraid not - atleast I wasn't able to glimpse anything relevant in their official changelog (http://www.courier-mta.org/changelog.html)
Comment 7 Tuan Van (RETIRED) gentoo-dev 2005-05-11 11:28:58 UTC
upstream responsed here: http://sourceforge.net/mailarchive/forum.php?thread_id=7193743&forum_id=6705
Comment 8 Thierry Carrez (RETIRED) gentoo-dev 2005-05-15 08:27:55 UTC
Upstream denied it, maybe our auditors should check it sometime.
Comment 9 Tavis Ormandy (RETIRED) gentoo-dev 2005-07-16 01:55:54 UTC
Closing as per upstream.