drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Denial of Service in SquirrelMail
Name: |
Denial of Service in SquirrelMail |
|
ID: |
USN-4669-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 16.04 LTS |
|
Datum: |
Do, 10. Dezember 2020, 23:52 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12970 |
|
Applikationen: |
Squirrelmail |
|
Originalnachricht |
--===============8324137396433300100== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="ok4qyuue5jztk4pf" Content-Disposition: inline
--ok4qyuue5jztk4pf Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-4669-1 December 10, 2020
squirrelmail vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
SquirrelMail could be made to crash if it received specially crafted input.
Software Description: - squirrelmail: Webmail for nuts
Details:
It was discovered that a cross-site scripting (XSS) vulnerability in SquirrelMail allows remote attackers to use malicious script content from HTML e-mail to execute code and/or provoke a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04 LTS: squirrelmail 2:1.4.23~svn20120406-2+deb8u3ubuntu0.16.04.2
In general, a standard system update will make all the necessary changes.
References: https://usn.ubuntu.com/4669-1 CVE-2019-12970
Package Information: https://launchpad.net/ubuntu/+source/squirrelmail/2:1.4.23~svn20120406-2+deb8u3ubuntu0.16.04.2
--ok4qyuue5jztk4pf Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEkCdEQ5T6DutSveCybUp5kL3izGYFAl/SUKAACgkQbUp5kL3i zGZ0iw//edSdNQwQbJlwmG0G3ydBvKuHTEwe6ypIhRNPRPtgKgjHhq1PMujws7Ur ieGL4+60CRTRZ61MaXB5Ndpey2Nuc0e7Fn3z1bp12tocz1zIG6+VJkMEj8cRT+us BIe7tiCFQseZy42jVHekCvv39T0hs99jcIxNIyRyawkxbGG16JQpLrVSRA5v4/RV WqaGqJ86Io/KfR3i0ZmZWpscN0K7uN+zF9nmUpTaAPmp35T5xIkXbdE4ZY+mBgTG ARD86MMYp5f6JoyrOOtVZQw/C4mfWolFLyIENpBYkOMG6BCsHDb1J8m3C+oy2sPd 5eKtFgmtr1WvBgnp6ZFJQPUekaFOlEd1b7KydeOKfKFGoreyEAUar+IBmZE186lK wGiU/qbODd8n/eNhknF551f3N184s/C6SbU1fP+jGUgVZrTrN0g+ewn8I7D5EFHr 8A8DGSu0c0SFS2vE4OC0UdEXkrDIFLvVINekArkbywscvsOX3OK3+LbZZtdbIvgv JYu5WSFex8DotYfTee5gfpsoWm9uCRTfMWTV1i9MwKFIrZe8pbeuIjX16havpdxM VfmTA7424zl7XCP8wMe41ZH/9PY4coynDeYJxEx4yylmBGhxTJdnKo3y+Ee4uKY9 UHgT3YRAk0b+LrkDh4VI9xWNFAvY1VQ50b+vRfitW8JjKXaXhxE= =wxJ1 -----END PGP SIGNATURE-----
--ok4qyuue5jztk4pf--
--===============8324137396433300100== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
|
|
|
|