Severity: : Medium
  CVE Kennungen: : CVE-2006-0377
  Advisory Date: 21 de июля de 2015

  DESCRIPTION

CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."

  INFORMATION EXPOSURE

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1000208
  Trend Micro Deep Security DPI Rule Name: 1000208 - SquirrelMail IMAP Command Injection Vulnerability

  AFFECTED SOFTWARE AND VERSION:

  • SquirrelMail SquirrelMail 1.4
  • SquirrelMail SquirrelMail 1.4-rc1
  • SquirrelMail SquirrelMail 1.4.1
  • SquirrelMail SquirrelMail 1.4.2
  • SquirrelMail SquirrelMail 1.4.3
  • SquirrelMail SquirrelMail 1.4.3-rc1
  • SquirrelMail SquirrelMail 1.4.3a
  • SquirrelMail SquirrelMail 1.4.3r3
  • SquirrelMail SquirrelMail 1.4.4
  • SquirrelMail SquirrelMail 1.4.4-rc1
  • SquirrelMail SquirrelMail 1.4.5
  • SquirrelMail SquirrelMail 1.4.6-rc1