_______________________________________________________________________
Package : squirrelmail
Date : June 23, 2009
Affected: Corporate 4.0
_______________________________________________________________________
Problem Description:
A vulnerability has been identified and corrected in squirrelmail:
The map_yp_alias function in functions/imap_general.php in SquirrelMail
before 1.4.19 allows remote attackers to execute arbitrary commands
via shell metacharacters in a username string that is used by the
ypmatch program. NOTE: this issue exists because of an incomplete
fix for CVE-2009-1579. (CVE-2009-1381)
Basically this is a syncronization with the latest squirrelmail package
found in Mandriva Cooker. The rpm changelog will reveal all the changes
(rpm -q --changelog squirrelmail).
The updated packages have been upgraded to the latest version of
squirrelmail to prevent this.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-1381
_______________________________________________________________________