CVE-2010-1637 Mail fetch plugin can be used as proxy for port scan

Bug #598077 reported by Andreas Wenning
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
squirrelmail (Ubuntu)
Fix Released
Undecided
Unassigned
Hardy
Fix Released
Low
Unassigned
Jaunty
Fix Released
Low
Unassigned
Karmic
Fix Released
Low
Unassigned
Lucid
Fix Released
Low
Unassigned
Maverick
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: squirrelmail

Description from http://squirrelmail.org/security/issue/2010-06-21

A vulnerability was reported in the SquirrelMail Mail Fetch plugin, wherein (when the plugin is activated by the administrator) a user is allowed to specify (without restriction) any port number for their external POP account settings. While the intention is to allow users to access POP3 servers using non-standard ports, this also allows malicious users to effectively port-scan any server through their SquirrelMail service (especially note that when a SquirrelMail server resides on a network behind a firewall, it may allow the user to explore the network topography (DNS scan) and services available (port scan) on the inside of (behind) that firewall). As this vulnerability is only exploitable post-authentication, and better more specific port scanning tools are freely available, we consider this vulnerability to be of very low severity. It has been fixed by restricting the allowable POP port numbers (with an administrator configuration override available).

visibility: private → public
Changed in squirrelmail (Ubuntu):
status: New → In Progress
Changed in squirrelmail (Ubuntu Lucid):
status: New → In Progress
Changed in squirrelmail (Ubuntu Jaunty):
status: New → In Progress
Changed in squirrelmail (Ubuntu Hardy):
status: New → In Progress
Changed in squirrelmail (Ubuntu Karmic):
status: New → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package squirrelmail - 2:1.4.20-1ubuntu1

---------------
squirrelmail (2:1.4.20-1ubuntu1) maverick; urgency=low

  * SECURITY UPDATE: (LP: #598077)
  * The Mail Fetch plugin allows remote authenticated users to bypass firewall
    restrictions and use SquirrelMail as a proxy to scan internal networks via
    a modified POP3 port number.
    - http://squirrelmail.org/security/issue/2010-06-21
    - CVE-2010-1637
    - Patch taken from upstream svn rev. 13951. Applied inline.
 -- Andreas Wenning <email address hidden> Thu, 24 Jun 2010 14:19:29 +0200

Changed in squirrelmail (Ubuntu Maverick):
status: In Progress → Fix Released
Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

Here comes a debdiff for lucid. Package tested and works in a chroot.

Changed in squirrelmail (Ubuntu Lucid):
status: In Progress → Confirmed
Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

And a debdiff for karmic. Tested likewise.

Changed in squirrelmail (Ubuntu Karmic):
status: In Progress → Confirmed
Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

Debdiff for jaunty. Tested as well.

Changed in squirrelmail (Ubuntu Jaunty):
status: In Progress → Confirmed
Revision history for this message
Andreas Wenning (andreas-wenning) wrote :

And lastly, here is one for hardy. Also tested in a hardy chroot.

Changed in squirrelmail (Ubuntu Hardy):
status: In Progress → Confirmed
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

ACK for hardy - lucid. Thanks Andreas!

Changed in squirrelmail (Ubuntu Lucid):
status: Confirmed → Fix Committed
importance: Undecided → Low
Changed in squirrelmail (Ubuntu Hardy):
status: Confirmed → Fix Committed
importance: Undecided → Low
Changed in squirrelmail (Ubuntu Jaunty):
status: Confirmed → Fix Committed
importance: Undecided → Low
Changed in squirrelmail (Ubuntu Karmic):
status: Confirmed → Fix Committed
importance: Undecided → Low
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package squirrelmail - 2:1.4.20-1ubuntu0.1

---------------
squirrelmail (2:1.4.20-1ubuntu0.1) lucid-security; urgency=low

  * SECURITY UPDATE: (LP: #598077)
  * The Mail Fetch plugin allows remote authenticated users to bypass firewall
    restrictions and use SquirrelMail as a proxy to scan internal networks via
    a modified POP3 port number.
    - http://squirrelmail.org/security/issue/2010-06-21
    - CVE-2010-1637
    - Patch taken from upstream svn rev. 13951. Applied inline.
 -- Andreas Wenning <email address hidden> Thu, 24 Jun 2010 14:18:27 +0200

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package squirrelmail - 2:1.4.19-1ubuntu0.2

---------------
squirrelmail (2:1.4.19-1ubuntu0.2) karmic-security; urgency=low

  * SECURITY UPDATE: (LP: #598077)
  * The Mail Fetch plugin allows remote authenticated users to bypass firewall
    restrictions and use SquirrelMail as a proxy to scan internal networks via
    a modified POP3 port number.
    - http://squirrelmail.org/security/issue/2010-06-21
    - CVE-2010-1637
    - Patch taken from upstream svn rev. 13951. Applied inline.
 -- Andreas Wenning <email address hidden> Thu, 24 Jun 2010 14:17:43 +0200

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package squirrelmail - 2:1.4.15-4ubuntu0.4

---------------
squirrelmail (2:1.4.15-4ubuntu0.4) jaunty-security; urgency=low

  * SECURITY UPDATE: (LP: #598077)
  * The Mail Fetch plugin allows remote authenticated users to bypass firewall
    restrictions and use SquirrelMail as a proxy to scan internal networks via
    a modified POP3 port number.
    - http://squirrelmail.org/security/issue/2010-06-21
    - CVE-2010-1637
    - Patch taken from upstream svn rev. 13951. Applied inline.
 -- Andreas Wenning <email address hidden> Thu, 24 Jun 2010 14:16:52 +0200

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package squirrelmail - 2:1.4.13-2ubuntu1.6

---------------
squirrelmail (2:1.4.13-2ubuntu1.6) hardy-security; urgency=low

  * SECURITY UPDATE: (LP: #598077)
  * The Mail Fetch plugin allows remote authenticated users to bypass firewall
    restrictions and use SquirrelMail as a proxy to scan internal networks via
    a modified POP3 port number.
    - http://squirrelmail.org/security/issue/2010-06-21
    - CVE-2010-1637
    - Patch taken from upstream svn rev. 13951. Applied inline.
 -- Andreas Wenning <email address hidden> Thu, 24 Jun 2010 14:16:06 +0200

Changed in squirrelmail (Ubuntu Hardy):
status: Fix Committed → Fix Released
Changed in squirrelmail (Ubuntu Jaunty):
status: Fix Committed → Fix Released
Changed in squirrelmail (Ubuntu Karmic):
status: Fix Committed → Fix Released
Changed in squirrelmail (Ubuntu Lucid):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.