CVE-2007-3634
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/07/2007
Last modified:
09/04/2025
Description
Unspecified vulnerability in the G/PGP (GPG) Plugin 2.0 for Squirrelmail 1.4.10a allows remote authenticated users to execute arbitrary commands via unspecified vectors, possibly related to the passphrase variable in the gpg_sign_attachment function, aka ZD-00000004. this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.
Impact
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:squirrelmail:gpg_plugin:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squirrelmail:squirrelmail:1.4.10a:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.immunitysec.com/pipermail/dailydave/2007-July/004448.html
- http://lists.immunitysec.com/pipermail/dailydave/2007-July/004452.html
- http://lists.immunitysec.com/pipermail/dailydave/2007-July/004453.html
- http://osvdb.org/45788
- http://www.attrition.org/pipermail/vim/2007-July/001703.html
- http://www.securityfocus.com/bid/24782
- http://www.wslabi.com/wabisabilabi/initPublishedBid.do
- http://lists.immunitysec.com/pipermail/dailydave/2007-July/004448.html
- http://lists.immunitysec.com/pipermail/dailydave/2007-July/004452.html
- http://lists.immunitysec.com/pipermail/dailydave/2007-July/004453.html
- http://osvdb.org/45788
- http://www.attrition.org/pipermail/vim/2007-July/001703.html
- http://www.securityfocus.com/bid/24782
- http://www.wslabi.com/wabisabilabi/initPublishedBid.do



