corigin.com

sofware news

SquirrelMail Repository Poisoned

Posted in Security (December 19, 2007 at 12:22 am)

SkiifGeek writes “Late last week the SquirrelMail team posted information on their site about a compromise to the main download repository for SquirrelMail that resulted in a critical flaw being introduced into two versions of the webmail application (1.4.11 and 1.4.12). After gaining access to the repository through a release maintainer’s compromised account (it is believed), the attackers made a slight modification to the release packages, modifying how a PHP global variable was handled. This introduced a remote file inclusion bug — leading to an arbitrary code execution risk on systems running the vulnerable versions of the software. The poisoning was identified by a difference in MD5 signatures for version 1.4.12. Version 1.4.13 is now available.”

Read more of this story at Slashdot.

…more

Coverity Reports Open Source Security Making Great StridesAnti-Virus Bug Briefly Identified Windows Explorer as MalwareHTML V5 and XHTML V2Microsoft Opens Its Security Research CookbooksMySQL Ends Enterprise Server Source Tarballs

No Responses to “SquirrelMail Repository Poisoned”

  1. Rudolph Says:

    to any xxx blog on the Internet!.

Leave a Reply

You must be logged in to post a comment.