Comment 8 for bug 598077

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package squirrelmail - 2:1.4.19-1ubuntu0.2

---------------
squirrelmail (2:1.4.19-1ubuntu0.2) karmic-security; urgency=low

  * SECURITY UPDATE: (LP: #598077)
  * The Mail Fetch plugin allows remote authenticated users to bypass firewall
    restrictions and use SquirrelMail as a proxy to scan internal networks via
    a modified POP3 port number.
    - http://squirrelmail.org/security/issue/2010-06-21
    - CVE-2010-1637
    - Patch taken from upstream svn rev. 13951. Applied inline.
 -- Andreas Wenning <email address hidden> Thu, 24 Jun 2010 14:17:43 +0200