Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-1381

Опубликовано: 22 мая 2009
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue exists because of an incomplete fix for CVE-2009-1579.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

hardy

released

2:1.4.13-2ubuntu1.4
intrepid

released

2:1.4.15-3ubuntu0.3
jaunty

released

2:1.4.15-4ubuntu0.2
karmic

not-affected

upstream

released

1.4.19

Показывать по

Ссылки на источники

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue exists because of an incomplete fix for CVE-2009-1579.

nvd
больше 16 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue exists because of an incomplete fix for CVE-2009-1579.

debian
больше 16 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMai ...

github
больше 3 лет назад

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue exists because of an incomplete fix for CVE-2009-1579.

6.8 Medium

CVSS2