Security researchers have uncovered a critical security hole in SquirrelMail, the open-source webmail project. Filippo Cavallarin and Dawid Golunski independently discovered a remote code execution hole in SquirrelMail version 1.4.22 and likely prior. That's the latest version, by the way, and is dated July 2011. The bug is a …

    Article title is misleading

    Makes it sound like there is a remote exploit in sendmail, when the problem is 100% confined to SquirrelMail.

      I agree should say something like "Do you use squirrelmail with sendmail.."

      on that note, as a squirrelmail user for 17 years now(even though I use roundcube today I still have SM installed for some family members who use it, last used SM in an office environment probably 2002), even back in the days when I did use sendmail I have always had squirrelmail just use smtp to localhost to send email. Not sure what the advantage ever might of been to using a local binary instead of smtp. I certainly never got any complaints.

      And by the tone of the whole article I also wonder if they really meant Sendmail the MTA or the sendmail executable.

      I don't mind, it got me to read it, and knowing that squirrel mail has a vuln is fine. But yeah, heart palpitations just before that point...

    Pretty sure Specsavers use this in some way.

    One of my customers was having trouble emailing them, so I had the Specsavers person email me so I could confirm their address was correct, and to see if I could mail them okay.

    Remember seeing SquirrelMail in the headers! :-D

  3. Number6

    SquirrelMail version 1.4.22 and likely prior. That's the latest version, by the way, and is dated July 2011.

    Interestingly enough, my Squirrelmail claims to be version 1.4.23 [SVN] so I guess while it's a snapshot of a stable version, it's not actually a stable version.

    Looks like it's fixed since the article published

    - Fixed insufficient sendmail command argument escaping (thanks

    to Mitchel Sahertian, Maor Shwartz, Dawid Golunski and Filippo

    Cavallarin for bringing this to our attention). [CVE-2017-7692]

      When you see El Vulture circling, you'd better look alive!

  5. P. Lee

    Do I understand this correctly?

    Only an authenticated user can run this attack?

  6. akfek


    The squirrelmail guy has been ill.

  7. jamesb2147


    Because not everyone wants to have cloud email from a provider beholden to foreign governments.

    Your servers, your data.

      Re: Why?

      ... therefore your choice of software. So why still using squirrelmail?

        Squirrelmail has been around for years, and trouble free in my case, and this vulnerability doesn't affect me as I use SMTP/IMAP as the front/back ends for it. As with others, I try to keep personal and family communications away from corporate data mining and branding. I've heard of Roundcube, but as I've been successful with Squirrelmail/Postfix/Mailman and others, which have been relatively straightforward to setup , configure and maintain compared to Sendmail which I used in the past. So I've had no reason to try Roundcube as Squirrelmail just works. Can you provide one ? It's Dovecote and trying to get proper email clients working sensibly on all sorts of tablet/phone platforms that have me tearing my hair out, so maintaining webmail for this kind of application (other than on proper desktops which have proper email clients) makes more sense as I only need to do it once for many client platforms.

        Why not use Squirrelmail + Sendmail? They've served me well for over ten years, I don't see any benefit in changing...

    "The bug is a classic failure to sanitize user input,"

    You'd really think there was a library that took care of that sort of stuff for you by now, wouldn't you?

      There are probably several such libraries. Where do you think these bugs live?

