CVE-2009-2964

Publication date 25 August 2009

Last updated 24 July 2024


Ubuntu priority

Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hijack the authentication of unspecified victims via features such as send message and change preferences, related to (1) functions/mailbox_display.php, (2) src/addrbook_search_html.php, (3) src/addressbook.php, (4) src/compose.php, (5) src/folders.php, (6) src/folders_create.php, (7) src/folders_delete.php, (8) src/folders_rename_do.php, (9) src/folders_rename_getname.php, (10) src/folders_subscribe.php, (11) src/move_messages.php, (12) src/options.php, (13) src/options_highlight.php, (14) src/options_identities.php, (15) src/options_order.php, (16) src/search.php, and (17) src/vcard.php.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
squirrelmail 9.10 karmic
Fixed 2:1.4.19-1ubuntu0.1
9.04 jaunty
Fixed 2:1.4.15-4ubuntu0.3
8.10 intrepid
Fixed 2:1.4.15-3ubuntu0.4
8.04 LTS hardy
Fixed 2:1.4.13-2ubuntu1.5
6.06 LTS dapper Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
squirrelmail