|
|
|
>> Mandriva Security Update Fixes SquirrelMail "plugins" Local File Inclusion Vulnerability
|
Mandriva has released updated packages to address a vulnerability identified in SquirrelMail. This flaw could be exploited by attackers to include or disclose the contents of local files with the privileges of the web server. For additional information, see : VUPEN/ADV-2006-2101
Affected Products
Corporate 3.0
Solution
Upgrade the affected package :
Corporate 3.0:
129dc516318e39d58c4fdef7d0a41f02 corporate/3.0/RPMS/squirrelmail-1.4.5-1.3.C30mdk.noarch.rpm
080b141df7eeefff678572a92899a100 corporate/3.0/RPMS/squirrelmail-poutils-1.4.5-1.3.C30mdk.noarch.rpm
98f98af3cc7d023838dba84c6fb0651c corporate/3.0/SRPMS/squirrelmail-1.4.5-1.3.C30mdk.src.rpm
Corporate 3.0/X86_64:
d82bab3f4b286eb2c3ad3bcbe4d0b23c x86_64/corporate/3.0/RPMS/squirrelmail-1.4.5-1.3.C30mdk.noarch.rpm
919fb3eb66dba1d83d19329b04283885 x86_64/corporate/3.0/RPMS/squirrelmail-poutils-1.4.5-1.3.C30mdk.noarch.rpm
98f98af3cc7d023838dba84c6fb0651c x86_64/corporate/3.0/SRPMS/squirrelmail-1.4.5-1.3.C30mdk.src.rpm
References
http://www.vupen.com/english/advisories/2006/2374 http://www.frsirt.com/english/reference/13555
ChangeLog
2006-06-16 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts with CVE, CWE, and CVSS when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |

|