CVE-2009-1579

EUVD-2009-1575
The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
squirrelmailsquirrelmail
𝑥
≤ 1.4.17
squirrelmailsquirrelmail
0.1
squirrelmailsquirrelmail
0.1.1
squirrelmailsquirrelmail
0.1.2
squirrelmailsquirrelmail
0.2
squirrelmailsquirrelmail
0.2.1
squirrelmailsquirrelmail
0.3
squirrelmailsquirrelmail
0.3.1
squirrelmailsquirrelmail
0.3pre1:pre1
squirrelmailsquirrelmail
0.3pre2:pre2
squirrelmailsquirrelmail
0.4
squirrelmailsquirrelmail
0.4pre1:pre1
squirrelmailsquirrelmail
0.4pre2:pre2
squirrelmailsquirrelmail
0.5
squirrelmailsquirrelmail
0.5pre1:pre1
squirrelmailsquirrelmail
0.5pre2:pre2
squirrelmailsquirrelmail
1.0
squirrelmailsquirrelmail
1.0.1
squirrelmailsquirrelmail
1.0.2
squirrelmailsquirrelmail
1.0.3
squirrelmailsquirrelmail
1.0.4
squirrelmailsquirrelmail
1.0.5
squirrelmailsquirrelmail
1.0.6
squirrelmailsquirrelmail
1.0pre1:pre1
squirrelmailsquirrelmail
1.0pre2:pre2
squirrelmailsquirrelmail
1.0pre3:pre3
squirrelmailsquirrelmail
1.1.0
squirrelmailsquirrelmail
1.1.1
squirrelmailsquirrelmail
1.1.2
squirrelmailsquirrelmail
1.1.3
squirrelmailsquirrelmail
1.2
squirrelmailsquirrelmail
1.2.0
squirrelmailsquirrelmail
1.2.0_rc3:_rc3
squirrelmailsquirrelmail
1.2.1
squirrelmailsquirrelmail
1.2.2
squirrelmailsquirrelmail
1.2.3
squirrelmailsquirrelmail
1.2.4
squirrelmailsquirrelmail
1.2.5
squirrelmailsquirrelmail
1.2.6
squirrelmailsquirrelmail
1.2.7
squirrelmailsquirrelmail
1.2.8
squirrelmailsquirrelmail
1.2.9
squirrelmailsquirrelmail
1.2.10
squirrelmailsquirrelmail
1.2.11
squirrelmailsquirrelmail
1.3.0
squirrelmailsquirrelmail
1.3.1
squirrelmailsquirrelmail
1.3.2
squirrelmailsquirrelmail
1.4
squirrelmailsquirrelmail
1.4.0
squirrelmailsquirrelmail
1.4.0_rc1:_rc1
squirrelmailsquirrelmail
1.4.0_rc2a:_rc2a
squirrelmailsquirrelmail
1.4.1
squirrelmailsquirrelmail
1.4.10
squirrelmailsquirrelmail
1.4.10a:a
squirrelmailsquirrelmail
1.4.11
squirrelmailsquirrelmail
1.4.12
squirrelmailsquirrelmail
1.4.15
squirrelmailsquirrelmail
1.4.15_rc1:_rc1
squirrelmailsquirrelmail
1.4.16
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
squirrelmail
dapper
ignored
hardy
Fixed 2:1.4.13-2ubuntu1.3
released
intrepid
Fixed 2:1.4.15-3ubuntu0.2
released
jaunty
Fixed 2:1.4.15-4ubuntu0.1
released
karmic
not-affected
References