Jump to content

Recommended Posts

Posted

The plugin affected are not something that is installed by default as far as I know, but there may be members that have installed it themselves.

 

Secunia writes (http://secunia.com/advisories/13791/):

Description:

LSS Security Team has reported two vulnerabilities in the Vacation plugin for SquirrelMail, which can be exploited by malicious, local users to gain escalated privileges and disclose sensitive information.

 

1) The vulnerability is caused due to an input validation error in the command line handling in "ftpfile" and allows injection of arbitrary shell commands. This can be exploited by supplying a specially crafted command line argument containing shell meta characters.

 

2) The vulnerability is caused due to an input validation error in "ftpfile", making it possible to disclose arbitrary files via directory traversal attacks.

 

The vulnerabilities have been reported in version 0.15 and prior.

 

Solution:

Remove the setuid bit from "ftpfile". This may affect functionality.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...