Vulnerabilities > CVE-2007-3634 - Remote Command Execution vulnerability in Squirrelmail GPG Plugin 2.0

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
squirrelmail

Summary

Unspecified vulnerability in the G/PGP (GPG) Plugin 2.0 for Squirrelmail 1.4.10a allows remote authenticated users to execute arbitrary commands via unspecified vectors, possibly related to the passphrase variable in the gpg_sign_attachment function, aka ZD-00000004. this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

Vulnerable Configurations

Part Description Count
Application
Squirrelmail
2

Statements

contributorMark J Cox
lastmodified2007-07-10
organizationRed Hat
statementNot vulnerable. This plugin is not shipped with Squirrelmail in Red Hat Enterprise Linux.