Lucene search

K
redhatRedHatRHSA-2009:1490
HistoryOct 08, 2009 - 12:00 a.m.

(RHSA-2009:1490) Moderate: squirrelmail security update

2009-10-0800:00:00
access.redhat.com
19

EPSS

0.004

Percentile

73.7%

SquirrelMail is a standards-based webmail package written in PHP.

Form submissions in SquirrelMail did not implement protection against
Cross-Site Request Forgery (CSRF) attacks. If a remote attacker tricked a
user into visiting a malicious web page, the attacker could hijack that
user’s authentication, inject malicious content into that user’s
preferences, or possibly send mail without that user’s permission.
(CVE-2009-2964)

Users of SquirrelMail should upgrade to this updated package, which
contains a backported patch to correct these issues.