Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-2753

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2011-2753
Last Modified 13 Feb 2012 11:07:48
Published 17 Jul 2011 04:55:01
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-2753

Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of unspecified victims via vectors involving (1) the empty trash implementation and (2) the Index Order (aka options_order) page, a different issue than CVE-2010-4555.

Vulnerable Systems

Application

  • Squirrelmail 0.1

  • Squirrelmail 0.1.1

  • Squirrelmail 0.1.2

  • Squirrelmail 0.2

  • Squirrelmail 0.2.1

  • Squirrelmail 0.3

  • Squirrelmail 0.3.1

  • Squirrelmail 0.3pre1

  • Squirrelmail 0.3pre2

  • Squirrelmail 0.4

  • Squirrelmail 0.4pre1

  • Squirrelmail 0.4pre2

  • Squirrelmail 0.5

  • Squirrelmail 0.5pre1

  • Squirrelmail 0.5pre2

  • Squirrelmail 1.0

  • Squirrelmail 1.0.1

  • Squirrelmail 1.0.2

  • Squirrelmail 1.0.3

  • Squirrelmail 1.0.4

  • Squirrelmail 1.0.5

  • Squirrelmail 1.0.6

  • Squirrelmail 1.0pre1

  • Squirrelmail 1.0pre2

  • Squirrelmail 1.0pre3

  • Squirrelmail 1.1.0

  • Squirrelmail 1.1.1

  • Squirrelmail 1.1.2

  • Squirrelmail 1.1.3

  • Squirrelmail 1.2

  • Squirrelmail 1.2.0

  • Squirrelmail 1.2.1

  • Squirrelmail 1.2.10

  • Squirrelmail 1.2.11

  • Squirrelmail 1.2.2

  • Squirrelmail 1.2.3

  • Squirrelmail 1.2.4

  • Squirrelmail 1.2.5

  • Squirrelmail 1.2.6

  • Squirrelmail 1.2.7

  • Squirrelmail 1.2.8

  • Squirrelmail 1.2.9

  • Squirrelmail 1.3.0

  • Squirrelmail 1.3.1

  • Squirrelmail 1.3.2

  • Squirrelmail 1.4

  • Squirrelmail 1.4.0

  • Squirrelmail 1.4.0-r1

  • Squirrelmail 1.4.1

  • Squirrelmail 1.4.10

  • Squirrelmail 1.4.10a

  • Squirrelmail 1.4.11

  • Squirrelmail 1.4.12

  • Squirrelmail 1.4.13

  • Squirrelmail 1.4.15

  • Squirrelmail 1.4.15rc1

  • Squirrelmail 1.4.16

  • Squirrelmail 1.4.17

  • Squirrelmail 1.4.18

  • Squirrelmail 1.4.19

  • Squirrelmail 1.4.2

  • Squirrelmail 1.4.2-r1

  • Squirrelmail 1.4.2-r2

  • Squirrelmail 1.4.2-r3

  • Squirrelmail 1.4.2-r4

  • Squirrelmail 1.4.2-r5

  • Squirrelmail 1.4.20

  • Squirrelmail 1.4.21

  • Squirrelmail 1.4.3

  • Squirrelmail 1.4.3a

  • Squirrelmail 1.4.3aa

  • Squirrelmail 1.4.4

  • Squirrelmail 1.4.5

  • Squirrelmail 1.4.6

  • Squirrelmail 1.4.6 Cvs

  • Squirrelmail 1.4.7

  • Squirrelmail 1.4.8

  • Squirrelmail 1.4.8.4fc6

  • Squirrelmail 1.4.9

  • Squirrelmail 1.4.9a


References

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=720694

CONFIRM - http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=revision&revision=14119

XF - squirrelmail-authentication-csrf(68586)

MANDRIVA - MDVSA-2011:123

DEBIAN - DSA-2291

REDHAT - RHSA-2012:0103

Related Patches

Red Hat 2012:0103-01 RHSA Moderate: squirrelmail security update for RHEL 4 x86

Red Hat 2012:0103-01 RHSA Moderate: squirrelmail security update for RHEL 5 x86

Red Hat 2012:0103-01 RHSA Moderate: squirrelmail security update for RHEL 4 x86_64

Red Hat 2012:0103-01 RHSA Moderate: squirrelmail security update for RHEL 5 x86_64


Last Updated: 27 May 2016 10:58:39