CVE-2009-1579

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
squirrelmailsquirrelmail
𝑥
≤ 1.4.17
squirrelmailsquirrelmail
0.1
squirrelmailsquirrelmail
0.1.1
squirrelmailsquirrelmail
0.1.2
squirrelmailsquirrelmail
0.2
squirrelmailsquirrelmail
0.2.1
squirrelmailsquirrelmail
0.3
squirrelmailsquirrelmail
0.3.1
squirrelmailsquirrelmail
0.3pre1:pre1
squirrelmailsquirrelmail
0.3pre2:pre2
squirrelmailsquirrelmail
0.4
squirrelmailsquirrelmail
0.4pre1:pre1
squirrelmailsquirrelmail
0.4pre2:pre2
squirrelmailsquirrelmail
0.5
squirrelmailsquirrelmail
0.5pre1:pre1
squirrelmailsquirrelmail
0.5pre2:pre2
squirrelmailsquirrelmail
1.0
squirrelmailsquirrelmail
1.0.1
squirrelmailsquirrelmail
1.0.2
squirrelmailsquirrelmail
1.0.3
squirrelmailsquirrelmail
1.0.4
squirrelmailsquirrelmail
1.0.5
squirrelmailsquirrelmail
1.0.6
squirrelmailsquirrelmail
1.0pre1:pre1
squirrelmailsquirrelmail
1.0pre2:pre2
squirrelmailsquirrelmail
1.0pre3:pre3
squirrelmailsquirrelmail
1.1.0
squirrelmailsquirrelmail
1.1.1
squirrelmailsquirrelmail
1.1.2
squirrelmailsquirrelmail
1.1.3
squirrelmailsquirrelmail
1.2
squirrelmailsquirrelmail
1.2.0
squirrelmailsquirrelmail
1.2.0_rc3:_rc3
squirrelmailsquirrelmail
1.2.1
squirrelmailsquirrelmail
1.2.2
squirrelmailsquirrelmail
1.2.3
squirrelmailsquirrelmail
1.2.4
squirrelmailsquirrelmail
1.2.5
squirrelmailsquirrelmail
1.2.6
squirrelmailsquirrelmail
1.2.7
squirrelmailsquirrelmail
1.2.8
squirrelmailsquirrelmail
1.2.9
squirrelmailsquirrelmail
1.2.10
squirrelmailsquirrelmail
1.2.11
squirrelmailsquirrelmail
1.3.0
squirrelmailsquirrelmail
1.3.1
squirrelmailsquirrelmail
1.3.2
squirrelmailsquirrelmail
1.4
squirrelmailsquirrelmail
1.4.0
squirrelmailsquirrelmail
1.4.0_rc1:_rc1
squirrelmailsquirrelmail
1.4.0_rc2a:_rc2a
squirrelmailsquirrelmail
1.4.1
squirrelmailsquirrelmail
1.4.10
squirrelmailsquirrelmail
1.4.10a:a
squirrelmailsquirrelmail
1.4.11
squirrelmailsquirrelmail
1.4.12
squirrelmailsquirrelmail
1.4.15
squirrelmailsquirrelmail
1.4.15_rc1:_rc1
squirrelmailsquirrelmail
1.4.16
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
squirrelmail
karmic
not-affected
jaunty
Fixed 2:1.4.15-4ubuntu0.1
released
intrepid
Fixed 2:1.4.15-3ubuntu0.2
released
hardy
Fixed 2:1.4.13-2ubuntu1.3
released
dapper
ignored
References