The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue exists because of an incomplete fix for CVE-2009-1579.
2009-05-22T20:30:00.703
2025-04-09T00:30:58.490
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | squirrelmail | imap_general.php | 1.2.2 | Yes |
| Application | squirrelmail | squirrelmail | 1.2.5 | Yes |
| Application | squirrelmail | squirrelmail | 1.2.6 | Yes |
| Application | squirrelmail | squirrelmail | 1.2.6-rc1 | Yes |
| Application | squirrelmail | squirrelmail | 1.2.7 | Yes |
| Application | squirrelmail | squirrelmail | 1.2.8 | Yes |
| Application | squirrelmail | squirrelmail | 1.2.9 | Yes |
| Application | squirrelmail | squirrelmail | 1.2.10 | Yes |
| Application | squirrelmail | squirrelmail | 1.2.11 | Yes |
| Application | squirrelmail | squirrelmail | 1.4.0 | Yes |
| Application | squirrelmail | squirrelmail | 1.4.0-r1 | Yes |
| Application | squirrelmail | squirrelmail | 1.4.1 | Yes |
| Application | squirrelmail | squirrelmail | 1.4.2 | No |
| Application | squirrelmail | squirrelmail | 1.4.2-r1 | No |
| Application | squirrelmail | squirrelmail | 1.4.2-r2 | No |
| Application | squirrelmail | squirrelmail | 1.4.2-r3 | No |
| Application | squirrelmail | squirrelmail | 1.4.2-r4 | No |
| Application | squirrelmail | squirrelmail | 1.4.2-r5 | No |
| Application | squirrelmail | squirrelmail | 1.4.3_rc1 | No |
| Application | squirrelmail | squirrelmail | 1.4.3_rc1 | No |
| Application | squirrelmail | squirrelmail1.4.19-1 | * | No |