æ å ±å¦çæ¨é²æ©æ§ã»ãã¥ãªãã£ã»ã³ã¿ã¼ï¼IPA/ISECï¼ã¨JPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ï¼JPCERT/CCï¼ã¯1æ7æ¥ãSquirrelMail Projectãæä¾ããã¦ã§ãã¡ã¼ã«ãSquirrelMailãã«è¤æ°ã®èå¼±æ§ã確èªãããã¨ãJapan Vulnerability Notesï¼JVNï¼ãã§çºè¡¨ãããææ°çã¸ã®ã¢ãããã¼ãã«ããããããã®èå¼±æ§ã解æ¶ã§ããã 1.4.0ã1.4.9aã®ãã¼ã¸ã§ã³ã«ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼ã®èå¼±æ§ãåå¨ãããæªç¨ãããã¨ãã¦ã¼ã¶ã¼ã®ã¦ã§ããã©ã¦ã¶ä¸ã§ä»»æã®ã¹ã¯ãªãããå®è¡ãããå¯è½æ§ãããã 1.4.19以åã®ãã¼ã¸ã§ã³ã«ãã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªï¼CSRFï¼ã®èå¼±æ§ãåå¨ãããæªç¨ãããã¨ããªã¢ã¼ãã®æ»æè ã«ããã¦ã¼ã¶ã¼ã®æå³ããªãã¡ã¼ã«ãéä¿¡ãããããè¨å®ãå¤æ´ããããããå¯è½æ§ãããã
{{#tags}}- {{label}}
{{/tags}}