FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-0377

This CVE name corresponds to:

Entered Topic
2006-02-24 squirrelmail -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-0377
Phase Assigned(20060123)

Description

CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."

References

Source Reference
CONFIRM http://www.squirrelmail.org/security/issue/2006-02-15
DEBIAN DSA-988
FEDORA FEDORA-2006-133
GENTOO GLSA-200603-09
MANDRIVA MDKSA-2006:049
REDHAT RHSA-2006:0283
SGI 20060501-01-U
SUSE SUSE-SR:2006:005
BID 16756
OVAL oval:org.mitre.oval:def:11470
VUPEN ADV-2006-0689
SECTRACK 1015662
SECUNIA 18985
SECUNIA 19131
SECUNIA 19130
SECUNIA 19176
SECUNIA 19205
SECUNIA 19960
SECUNIA 20210
XF squirrelmail-mailbox-imap-injection(24849)