Ravens PHP Scripts

SquirrelMail Package Compromise
Date: Friday, December 14, 2007 @ 11:31:54 CST
Topic: Security


SECUNIA ADVISORY ID: SA28095

VERIFY ADVISORY: http://secunia.com/advisories/28095/

CRITICAL: Moderately critical

IMPACT: Unknown

SOFTWARE: SquirrelMail 1.x - http://secunia.com/product/288/

DESCRIPTION: A package compromise with unknown impact has been reported in SquirrelMail. The vendor reports that the squirrelmail package has been modified post release. This affects 1.4.12 packages downloaded after 8th December 2007.



SOLUTION: Check the MD5 sum of the package and apply the corrected package if they do not match.
http://squirrelmail.org/download.php


ea5e750797628c9f0f247009f8ae0e14 squirrelmail-1.4.12.tar.bz2
d17c1d9f1ee3dde2c1c21a22fc4f9d0e squirrelmail-1.4.12.tar.gz
3f6514939ea1ebf69f6f8c92781886ab squirrelmail-1.4.12.zip

PROVIDED AND/OR DISCOVERED BY: Reported by the vendor.

ORIGINAL ADVISORY:
http://squirrelmail.org/index.php
http://archives.neohapsis.com/archives/bugtraq/2007-12/0180.html






This article comes from Ravens PHP Scripts
https://www.ravenphpscripts.com

The URL for this story is:
https://www.ravenphpscripts.com/modules.php?name=News&file=article&sid=3169