Debian Upstream developers noticed that an unsanitised variable could lead to cross site scripting.
Debian Security Advisory DSA 662-1                                        Martin Schulze
February 1st, 2005            
Package        : squirrelmail
Vulnerability  : several
Problem-Type   : remote
Debian-specific: no
CVE ID         : CAN-2005-0104 CAN-2005-0152
Debian Bug     : 292714

Several vulnerabilities have been discovered in Squirrelmail, a
commonly used webmail system.  The Common Vulnerabilities and
Exposures project identifies the following problems:


    Upstream developers noticed that an unsanitised variable could
    lead to cross site scripting.


    Grant Hollingworth discovered that under certain circumstances URL
    manipulation could lead to the execution of arbitrary code with
    the privileges of www-data.  This problem only exists in version
    1.2.6 of Squirrelmail.

For the stable distribution (woody) these problems have been fixed in
version 1.2.6-2.

For the unstable distribution (sid) the problem that affects unstable
has been fixed in version 1.4.4-1.

We recommend that you upgrade your squirrelmail package.

