Download Squirrelmail 1.43a XSS Patch
The latest version of Squirrelmail is version 1.43a. This dates back to early June, but a bug was recently discovered. Instead of releasing a new version, the developers behind this PHP email program have opted to release a 2KB patch. The bug is related to cross site scripting and the release notes tell more about it and how to fix the vulnerability:
There is a cross site scripting issue in the decoding of encoded text in certain headers. SquirrelMail correctly decodes the specially crafted header, but doesn’t sanitize the decoded strings. To apply this patch, copy the sm143a-xss.diff file into the base SquirrelMail directory, and follow the command:
- patch -p0 [break]
Version number | 1.43a XSS Patch |
Operating systems | Windows 9x, Windows NT, Windows 2000, Linux, Windows XP |
Website | squirrelmail |
Download | |
File size |
2.00kB |
License type | GPL |