• [SECURITY] [DSA 2091-1] New squirrelmail packages fix cross-site reques

    From Luciano Bello@1:229/2 to All on Thu Aug 12 22:30:03 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2091-1 [email protected] http://www.debian.org/security/ Luciano Bello
    August 12, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : squirrelmail
    Vulnerability : No user-specific token implemented
    Problem type : remote
    Debian-specific: no
    Debian bug : 543818
    CVE ID : CVE-2009-2964 CVE-2010-2813

    SquirrelMail, a webmail application, does not employ a user-specific token
    for webforms. This allows a remote attacker to perform a Cross Site Request Forgery (CSRF) attack. The attacker may hijack the authentication of unspecified victims and send messages or change user preferences among other actions, by tricking the victim into following a link controled by the offender.

    In addition, a denial-of-service was fixed, which could be triggered when a passwords containing 8-bit characters was used to log in (CVE-2010-2813).

    For the stable distribution (lenny), these problems have been fixed in
    version 1.4.15-4+lenny3.1.

    For the testing distribution (squeeze) and the unstable distribution (sid), these problems have been fixed in version 1.4.21-1.

    We recommend that you upgrade your squirrelmail packages.


    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelmail_1.4.15-4+lenny3.1.diff.gz
    Size/MD5 checksum: 34647 2251562662703a0d8e4f0de309ca60a6
    http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelmail_1.4.15.orig.tar.gz
    Size/MD5 checksum: 621320 87b466fef98e770307afffd75fe25589
    http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelmail_1.4.15-4+lenny3.1.dsc
    Size/MD5 checksum: 1240 a4e2ab21379259946f02a1d30831fe6d

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/s/squirrelmail/squirrelmail_1.4.15-4+lenny3.1_all.deb
    Size/MD5 checksum: 615152 d08549fd86ffec2ae16b36e358f50cd6


    These files will probably be moved into the stable distribution on
    its next update.

    - ---------------------------------------------------------------------------------
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: [email protected]
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.10 (GNU/Linux)

    iQEcBAEBAgAGBQJMZFbAAAoJEOxfUAG2iX57E9wH/2R7hpqY9l0OTtMT+TpEP6ld SWMx1rhE+Vf8nss3AKSx88uAn0szgS0zyVdBuGbksFsKDsLLAyreajwyqyNqYWdf +saBoZHbOXsE3xQUp1ceHJQ5LO3hPl8e7PlSfb91TVX0PTwjAbflIICGXNXjsT3j 2gQRUWI8VtIbKNaTh0erSS2tU0CHdcWxcVjCmPLJxrDZ5jy9vTgiyc2secI6PLLQ uXpTBTC4ORRcui1L464cDb0a0xdX9s3qBu5PGydYwGyCMXsf4Vs8atejBUIK/XZq 2aLNcAQuwNHttZtlRuig8LLmavpVEvDXErlFhETOd6UFCz5sVq9yfrMMT3ECli0=
    =9dTP
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)