Vulnerability Bulletins

DSA-4168 squirrelmail - security update

   
Affected software Debian
 
Florian Grunow and Birk Kauer of ERNW discovered a path traversalvulnerability in SquirrelMail, a webmail application, allowing anauthenticated remote attacker to retrieve or delete arbitrary filesvia mail attachment.

More info:

https://www.debian.org/security/2018/dsa-4168