Home page logo
/

oss-sec logo oss-sec mailing list archives

Re: Strange CVE situation (at least one ID should come of this)
From: Kurt Seifried <kseifried () redhat com>
Date: Mon, 03 Dec 2012 22:26:29 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 10/26/2012 01:54 PM, Josh Bressers wrote:
Hello,

This Squirrelmail plugin came to my attention a few weeks back: 
http://squirrelmail.org/plugin_view.php?id=117

It's from 2004, which is suspect in itself, but I took a look after
someone asked. It's pretty scary in there.

If I was to list the security problems I found after a few minutes
of looking, they are:

* It uses MD5 passwords

Going with this one since there's a good number of MD5 related CVE's
already.

Please use CVE-2012-5623 for this issue.

* The shadow file is directly modified without locking (which could
lead to a race condition) * If you get the password wrong, it
doesn't unlink the empty temporary file.

None are really a big deal, you *could* run this and probably never
notice these problems.

Fundamentally though, this thing should get one CVE ID that
basically say "don't use this". How have situations like this been
handled in the past?

I mailed the Squirrelmail security team. They never responded.
Regardless of their response though, the plugin site says it has
been downloaded more than 100K times, so I suspect it's still in
use somewhere. My goal in this CVE request is to raise awareness so
hopefully people stop using this (and get the Squirrelmail guys to
remove it from their site).

Thanks.



- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBAgAGBQJQvYmFAAoJEBYNRVNeJnmTnQ4P/iA61xUAae2kvq3DyFH3E3A0
yzwTleZMOUSd5hDYSpk29OZPRMpnoX6q/fUe2EV/zyw7paY9JekuByvYy9WBaWtO
2SfiwyEwh+LnxsjZ8SjS+xOOQ3SRojdty6dlq+cbUTsh9QE+Y9KcAs55Cn9z02e0
23XhgVIImRfYp0qCkZbXBw1q8C1swttfMx4xR1HPh5vsxXfC9ExzHjJPe+0Gippg
XGBD/TvDs777on1n+254gn5eDisnZOt37NQxS48zTb9dPVVBhLngTT6ENafkdTxw
DlUljG35R3IugYJs5kX5N1ktEYLWChoxuygTgbAlGdEqoGHI/Q1qFYO8qp+60af8
mXNN3o64oM3ESIGI2660/EZhoLfaN20l7QI1paDUHxEprUv/lHt0vv1fINZMWqGZ
9qNxBkgFg0iA4z0n41xxDK3J0Utd5KvDt00JOnpfm9h3zb8Ed3AlpbDkDJO3c/TH
bLIq/RH9wuRh1mcVEqlzzWWk/K3tNZgRfBHoy1Jr2e0YxyVAr4UkWFGkZLMqXtql
LWru3BAOqX/ltVP2Ch1cux7XD/0hwD3CPfcMu73psKoh5Ln9rtz13Ux5e4hKCLuO
zRSCqd9TgKzx917L/tnEq9oXQBFfCZOQqCPAtOSQPYGWGFZx0do9pCZ2Z3haEC3D
5j4YcPuG4evM2S5G2aoZ
=6R68
-----END PGP SIGNATURE-----


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault