CVE-2006-3665

Publication date 18 July 2006

Last updated 17 July 2025


Ubuntu priority

Description

SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while "cookie theft" is frequently associated with XSS, the vendor disclosure is too vague to be certain of this.

Status

Package Ubuntu Release Status
squirrelmail 9.10 karmic
Fixed 2:1.4.7-1
9.04 jaunty
Fixed 2:1.4.7-1
8.10 intrepid
Fixed 2:1.4.7-1
8.04 LTS hardy
Fixed 2:1.4.7-1
7.10 gutsy
Fixed 2:1.4.7-1
7.04 feisty
Fixed 2:1.4.7-1
6.10 edgy
Fixed 2:1.4.7-1
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities