CVE Vulnerabilities

CVE-2009-1381

Published: May 22, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue exists because of an incomplete fix for CVE-2009-1579.

Affected Software

NameVendorStart VersionEnd Version
Imap_general.phpSquirrelmail1.2.2 (including)1.2.2 (including)
SquirrelmailSquirrelmail1.2.5 (including)1.2.5 (including)
SquirrelmailSquirrelmail1.2.6 (including)1.2.6 (including)
SquirrelmailSquirrelmail1.2.6-rc1 (including)1.2.6-rc1 (including)
SquirrelmailSquirrelmail1.2.7 (including)1.2.7 (including)
SquirrelmailSquirrelmail1.2.8 (including)1.2.8 (including)
SquirrelmailSquirrelmail1.2.9 (including)1.2.9 (including)
SquirrelmailSquirrelmail1.2.10 (including)1.2.10 (including)
SquirrelmailSquirrelmail1.2.11 (including)1.2.11 (including)
SquirrelmailSquirrelmail1.4.0 (including)1.4.0 (including)
SquirrelmailSquirrelmail1.4.0-r1 (including)1.4.0-r1 (including)
SquirrelmailSquirrelmail1.4.1 (including)1.4.1 (including)
SquirrelmailSquirrelmail1.4.2 (including)1.4.2 (including)
SquirrelmailSquirrelmail1.4.2-r1 (including)1.4.2-r1 (including)
SquirrelmailSquirrelmail1.4.2-r2 (including)1.4.2-r2 (including)
SquirrelmailSquirrelmail1.4.2-r3 (including)1.4.2-r3 (including)
SquirrelmailSquirrelmail1.4.2-r4 (including)1.4.2-r4 (including)
SquirrelmailSquirrelmail1.4.2-r5 (including)1.4.2-r5 (including)
SquirrelmailSquirrelmail1.4.3_rc1 (including)1.4.3_rc1 (including)
SquirrelmailSquirrelmail1.4.3_rc1-r1 (including)1.4.3_rc1-r1 (including)
Squirrelmail1.4.19-1Squirrelmail**
SquirrelmailUbuntudapper*
SquirrelmailUbuntuhardy*
SquirrelmailUbuntuintrepid*
SquirrelmailUbuntujaunty*
SquirrelmailUbuntuupstream*

References