CVE-2009-1579
Publication date 14 May 2009
Last updated 24 July 2024
Ubuntu priority
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.
Status
Package | Ubuntu Release | Status |
---|---|---|
squirrelmail | 9.10 karmic |
Not affected
|
9.04 jaunty |
Fixed 2:1.4.15-4ubuntu0.1
|
|
8.10 intrepid |
Fixed 2:1.4.15-3ubuntu0.2
|
|
8.04 LTS hardy |
Fixed 2:1.4.13-2ubuntu1.3
|
|
6.06 LTS dapper | Ignored end of life |