Re: [SM-USERS] SquirrelMail 1.4.8 released - fixes variable overwriting attack

2006-08-12 Thread Richard Klein
Richard Klein wrote: > Thijs Kinkhorst wrote: >> http://www.squirrelmail.org/patches/sqm1.4.7-expired-post-fix-full.patch > > Where can I find documentation on how to apply this patch? I found my answer here: http://www.squirrelmail.org/wiki/PatchingSquirrelMail Have a great weekend! -- Rich --

Re: [SM-USERS] SquirrelMail 1.4.8 released - fixes variable overwriting attack

2006-08-12 Thread Richard Klein
Thijs Kinkhorst wrote: > http://www.squirrelmail.org/patches/sqm1.4.7-expired-post-fix-full.patch Where can I find documentation on how to apply this patch? Thanks! -- Rich - Using Tomcat but need to do more? Need to support

[SM-USERS] SquirrelMail 1.4.8 released - fixes variable overwriting attack

2006-08-11 Thread Thijs Kinkhorst
Hello all, Today SquirrelMail version 1.4.8 has been released with a collection of bugfixes and an important security fix. It was possible for an authenticated user to overwrite random variables in the compose.php script. This may open up possible attack vectors like reading or overwriting a user'