Peaches Posted May 13, 2009 Report Share Posted May 13, 2009 13 May 2009, 12:31Security Update for SquirrelMail "The SquirrelMail developers have announced the release of version 1.4.18 of their open source standards based webmail package. The update fixes multiple security problems, including several cross-site scripting (XSS) vulnerabilities and a session fixation issue, which could be used to steal user log-in credentials.A "dangerous" server-side code execution vulnerability has also been patched, however, the developers do not provide any other details. The release also includes three new languages and enhancements to the filter plug-ins and address book system.Version 1.4.18 is available to download and all users are advised to update. SquirrelMail is released under the GNU General Public License (GPL). "See also: Security, an overview of known SquirrelMail security issues.Heise security - http://www.h-online.com/security/Security-...l--/news/113276 Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.