SB2018040901 - Debian update for squirrelmail
Published: April 9, 2018
Security Bulletin ID
SB2018040901
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Path traversal (CVE-ID: CVE-2018-8741)
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information on the target system.The weakness exists due to input validation flaw in 'Deliver.class.php'. A remote attacker can upload a file with a specially crafted filename containing directory traversal characters (e.g., '../'), cause the system to attach arbitrary files to an email message with the privileges of the target PHP process and obtain or delete arbitrary files with the privileges of the target PHP process.
Remediation
Install update from vendor's website.