
SquirrelMail IMAP Command Injection Vulnerability
2015年7月21日
危険度: : 中
CVE識別番号: CVE-2006-0377
概要
CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."
トレンドマイクロの対策
Apply associated Trend Micro DPI Rules.
対応方法
Trend Micro Deep Security DPI Rule Number: 1000208
Trend Micro Deep Security DPI Rule Name: 1000208 - SquirrelMail IMAP Command Injection Vulnerability
影響を受けるソフトウェア
- SquirrelMail SquirrelMail 1.4
- SquirrelMail SquirrelMail 1.4-rc1
- SquirrelMail SquirrelMail 1.4.1
- SquirrelMail SquirrelMail 1.4.2
- SquirrelMail SquirrelMail 1.4.3
- SquirrelMail SquirrelMail 1.4.3-rc1
- SquirrelMail SquirrelMail 1.4.3a
- SquirrelMail SquirrelMail 1.4.3r3
- SquirrelMail SquirrelMail 1.4.4
- SquirrelMail SquirrelMail 1.4.4-rc1
- SquirrelMail SquirrelMail 1.4.5
- SquirrelMail SquirrelMail 1.4.6-rc1