Due to the package compromise of SquirrelMail 1.4.11, and 1.4.12, we are forced to release 1.4.13. Tests showed that the package alterations introduce a high risk security issue, allowing remote inclusion of files. These changes would allow a remote user the ability to execute exploit code on a victim machine, without any user interaction on the victim’s server. This could grant the attacker the ability to deploy further code on the victim’s server. New patched version is available for download at squirrelmail.org