==========================================================================
Ubuntu Security Notice USN-4669-1
December 10, 2020
squirrelmail vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 16.04 LTS
Summary:
SquirrelMail could be made to crash if it received specially crafted
input.
Software Description:
– squirrelmail: Webmail for nuts
Details:
It was discovered that a cross-site scripting (XSS) vulnerability in
SquirrelMail allows remote attackers to use malicious script content from
HTML e-mail to execute code and/or provoke a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS:
squirrelmail 2:1.4.23~svn20120406-2+deb8u3ubuntu0.16.04.2
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4669-1
CVE-2019-12970
Package Information:
https://launchpad.net/ubuntu/+source/squirrelmail/2:1.4.23~svn20120406-2+deb8u3ubuntu0.16.04.2
—–BEGIN PGP SIGNATURE—–
iQIzBAABCgAdFiEEkCdEQ5T6DutSveCybUp5kL3izGYFAl/SUKAACgkQbUp5kL3i
zGZ0iw//edSdNQwQbJlwmG0G3ydBvKuHTEwe6ypIhRNPRPtgKgjHhq1PMujws7Ur
ieGL4+60CRTRZ61MaXB5Ndpey2Nuc0e7Fn3z1bp12tocz1zIG6+VJkMEj8cRT+us
BIe7tiCFQseZy42jVHekCvv39T0hs99jcIxNIyRyawkxbGG16JQpLrVSRA5v4/RV
WqaGqJ86Io/KfR3i0ZmZWpscN0K7uN+zF9nmUpTaAPmp35T5xIkXbdE4ZY+mBgTG
ARD86MMYp5f6JoyrOOtVZQw/C4mfWolFLyIENpBYkOMG6BCsHDb1J8m3C+oy2sPd
5eKtFgmtr1WvBgnp6ZFJQPUekaFOlEd1b7KydeOKfKFGoreyEAUar+IBmZE186lK
wGiU/qbODd8n/eNhknF551f3N184s/C6SbU1fP+jGUgVZrTrN0g+ewn8I7D5EFHr
8A8DGSu0c0SFS2vE4OC0UdEXkrDIFLvVINekArkbywscvsOX3OK3+LbZZtdbIvgv
JYu5WSFex8DotYfTee5gfpsoWm9uCRTfMWTV1i9MwKFIrZe8pbeuIjX16havpdxM
VfmTA7424zl7XCP8wMe41ZH/9PY4coynDeYJxEx4yylmBGhxTJdnKo3y+Ee4uKY9
UHgT3YRAk0b+LrkDh4VI9xWNFAvY1VQ50b+vRfitW8JjKXaXhxE=
=wxJ1
—–END PGP SIGNATURE—–
—