Summary
The remote host is missing updates announced in
advisory GLSA 201001-08.
Solution
All SquirrelMail users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=mail-client/squirrelmail-1.4.19'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20201001-08 http://bugs.gentoo.org/show_bug.cgi?id=269567
http://bugs.gentoo.org/show_bug.cgi?id=270671
Insight
Multiple vulnerabilities were found in SquirrelMail of which the worst results in remote code execution.
Severity
Classification
-
CVE CVE-2009-1381, CVE-2009-1578, CVE-2009-1579, CVE-2009-1580, CVE-2009-1581 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities