CVE-2009-0030

Publication date 21 January 2009

Last updated 4 August 2025


Ubuntu priority

Description

A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.

Status

Package Ubuntu Release Status
squirrelmail 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
6.06 LTS dapper
Not affected


Access our resources on patching vulnerabilities