CVE-2009-1580

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.

References

http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html

http://secunia.com/advisories/35052

http://secunia.com/advisories/35073

http://secunia.com/advisories/35140

http://secunia.com/advisories/40220

http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/doc/ChangeLog

http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&revision=13676

http://support.apple.com/kb/HT4188

http://www.debian.org/security/2009/dsa-1802

http://www.mandriva.com/security/advisories?name=MDVSA-2009:110

http://www.securityfocus.com/bid/34916

http://www.squirrelmail.org/security/issue/2009-05-11

http://www.vupen.com/english/advisories/2009/1296

http://www.vupen.com/english/advisories/2010/1481

https://bugzilla.redhat.com/show_bug.cgi?id=500358

https://exchange.xforce.ibmcloud.com/vulnerabilities/50462

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10107

https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00566.html

https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00572.html

https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00577.html

Details

Source: MITRE

Published: 2009-05-14

Updated: 2017-09-29

Type: CWE-287

Risk Information

CVSS v2

Base Score: 5.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Impact Score: 4.9

Exploitability Score: 8.6

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:squirrelmail:squirrelmail:0.1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.1.1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.1.2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.2.1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.3:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.3.1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.3pre1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.3pre2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.4:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.4pre1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.4pre2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.5:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.5pre1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:0.5pre2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.0:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.0.1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.0.2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.0.3:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.0.4:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.0.5:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.0.6:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.0pre1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.0pre2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.0pre3:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.1.0:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.1.2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.1.3:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.0:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.0:rc3:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.3:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.4:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.5:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.6:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.7:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.8:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.9:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.10:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.2.11:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.3.0:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4:rc1:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.0:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.0:rc1:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.0:rc2a:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.1:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.2:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.3:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.3:r3:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.3:rc1:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.3a:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.3aa:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.4:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.4:rc1:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.5:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.6:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.6:rc1:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.7:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.8.4fc6:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.9:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.9a:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.10a:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.11:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.12:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.15:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.15:rc1:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:1.4.16:*:*:*:*:*:*:*

cpe:2.3:a:squirrelmail:squirrelmail:*:*:*:*:*:*:*:* versions up to 1.4.17 (inclusive)

cpe:2.3:a:squirrelmail:squirrelmail:1.44:*:*:*:*:*:*:*

Tenable Plugins

View all (14 total)

IDNameProductFamilySeverity
67794Oracle Linux 3 / 4 / 5 : squirrelmail (ELSA-2009-0057)NessusOracle Linux Local Security Checks
medium
800793Mac OS X 10.6 < 10.6.4 Multiple VulnerabilitiesLog Correlation EngineOperating System Detection
high
5571Mac OS X 10.6 < 10.6.4 Multiple VulnerabilitiesNessus Network MonitorGeneric
critical
47024Mac OS X Multiple Vulnerabilities (Security Update 2010-004)NessusMacOS X Local Security Checks
high
47023Mac OS X 10.6.x < 10.6.4 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
high
44897GLSA-201001-08 : SquirrelMail: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
38859Debian DSA-1802-2 : squirrelmail - several vulnerabilitiesNessusDebian Local Security Checks
medium
38776openSUSE 10 Security Update : squirrelmail (squirrelmail-6242)NessusSuSE Local Security Checks
medium
38750Fedora 10 : squirrelmail-1.4.18-1.fc10 (2009-4880)NessusFedora Local Security Checks
medium
38749Fedora 11 : squirrelmail-1.4.18-1.fc11 (2009-4875)NessusFedora Local Security Checks
medium
38748Fedora 9 : squirrelmail-1.4.18-1.fc9 (2009-4870)NessusFedora Local Security Checks
medium
35429RHEL 3 / 4 / 5 : squirrelmail (RHSA-2009:0057)NessusRed Hat Local Security Checks
medium
35424CentOS 3 / 4 / 5 : squirrelmail (CESA-2009:0057)NessusCentOS Local Security Checks
medium
5037SquirrelMail < 1.4.18 Multiple VulnerabilitiesNessus Network MonitorCGI
high