SquirrrelMail Vulnerability
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- :
- SquirrrelMail Vulnerability
SquirrrelMail Vulnerability
25-04-2017 12:39 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Hi,
I seem to recall that Plusnet Webmail is implemented with SquirrelMail.
Not sure which version you are running, but I think you need to look at this for the latest 1.4.22 release:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7692
http://securityaffairs.co/wordpress/58336/hacking/squirrelmail-rce.html
Thanks, Neal.
Re: SquirrrelMail Vulnerability
25-04-2017 4:13 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Already aware, thanks Neal.
Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵
Re: SquirrrelMail Vulnerability
26-04-2017 10:53 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I use SM 1.4.23 as a webmail solution elsewhere so this interests me.
I looks like SM haven't released an official patch but the person who found the vulnerability released an unofficial patch? Just curious what the solution might be beyond switching webmail solutions?
Re: SquirrrelMail Vulnerability
26-04-2017 11:06 AM - edited 26-04-2017 11:07 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
It's specific to installations that are configured to use Sendmail, so configuring Squirrel to use SMTP instead would be one way to ensure that you're not vulnerable.
Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵
Re: SquirrrelMail Vulnerability
26-04-2017 12:48 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I would take a guess that Plusnet would be using SMTP anyway with SquirrelMail, so from what @bobpullen has said, this vulnerability would affect them.
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: SquirrrelMail Vulnerability
27-04-2017 3:24 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@pjmarsh wrote:
... so from what @bobpullen has said, this vulnerability would affect them.
I assume you meant to type wouldn't?
Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵
Re: SquirrrelMail Vulnerability
27-04-2017 3:34 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Sorry, @bobpullen, yes, that's exactly what I meant!
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page