CVE-2007-6348

Description

From CVE.org

SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, which allows remote attackers to execute arbitrary code.

Statement

The versions of SquirrelMail packages shipped in Red Hat Enterprise Linux 3, 4, and 5 were not affected by this issue. In addition, the Red Hat Product Security have verified that the malicious code is not part of released Red Hat Enterprise Linux squirrelmail packages.

Frequently Asked Questions

Want to get errata notifications? Sign up here.