SquirrelMail CVE-2017-7692

rpvw

Well-Known Member
Jul 18, 2013
1,101
459
113
UK
cPanel Access Level
Root Administrator
Reports are emerging about a remote code execution hole in SquirrelMail version 1.4.22 and earlier.

Apparently this was allocated CVE-2017-5181 but remains unresolved.

Any thoughts from cPanel security team ? or should we disable the service pending release of a patch from upstream ?
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,908
2,218
463
Hello @rpvw,

It looks like the instance of SquirrelMail offered through cPanel isn't affected by this vulnerability because we don't use the Sendmail MTA:

Code:
grep useSendmail /usr/local/cpanel/base/3rdparty/squirrelmail/config/config.php
$useSendmail            = false;
However, as mentioned, internal case CPANEL-12702 is open to assess that report and ensure the instance of SquirrelMail offered through cPanel is updated to patch against this vulnerability. Feel free to monitor our change logs to see when the resolution is included:

64 Change Log - Change Logs - cPanel Documentation

Thank you.
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,908
2,218
463
Hello,

To update, this was addressed in cPanel 64.0.22:

Fixed case CPANEL-12702: Update cpanel-squirrelmail to 2012.12.09-4.cp1158.

Thank you.