Horde Application Framework Input Validation Vulnerabilities
BID:15806
Info
Horde Application Framework Input Validation Vulnerabilities
| Bugtraq ID: | 15806 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-4190 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2005 12:00AM |
| Updated: | Mar 19 2015 08:48AM |
| Credit: | Discovered by Johannes Greil. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 7 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise Desktop 10 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Office Server S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Professional 7.3 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server Horde Project Horde 3.0.7 Horde Project Horde 3.0.6 Horde Project Horde 3.0.4 -RC 2 Horde Project Horde 3.0.4 -RC 1 Horde Project Horde 3.0.4 Horde Project Horde 3.0.3 Horde Project Horde 3.0.2 Horde Project Horde 3.0.1 Horde Project Horde 3.0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Horde Project Horde 3.0.8 |
Discussion
Horde Application Framework Input Validation Vulnerabilities
Horde Application Framework is prone to multiple input-validation vulnerabilities. Remote attackers could exploit these vulnerabilities to perform cross-site scripting attacks to execute arbitrary HTML and script code in the browser of a vulnerable user.
Horde Application Framework 3.0.7 and earlier are affected by these issues.
Horde Application Framework is prone to multiple input-validation vulnerabilities. Remote attackers could exploit these vulnerabilities to perform cross-site scripting attacks to execute arbitrary HTML and script code in the browser of a vulnerable user.
Horde Application Framework 3.0.7 and earlier are affected by these issues.
Exploit / POC
Horde Application Framework Input Validation Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
Horde Application Framework Input Validation Vulnerabilities
Solution:
These issues have been addressed in Horde 3.0.8.
Please see the references for more information and vendor advisories.
Horde Project Horde 3.0
Horde Project Horde 3.0.1
Horde Project Horde 3.0.2
Horde Project Horde 3.0.3
Horde Project Horde 3.0.4 -RC 1
Horde Project Horde 3.0.4 -RC 2
Horde Project Horde 3.0.4
Horde Project Horde 3.0.6
Horde Project Horde 3.0.7
Solution:
These issues have been addressed in Horde 3.0.8.
Please see the references for more information and vendor advisories.
Horde Project Horde 3.0
-
Horde horde-3.0.8.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.0.8.tar.gz
Horde Project Horde 3.0.1
-
Horde horde-3.0.8.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.0.8.tar.gz
Horde Project Horde 3.0.2
-
Horde horde-3.0.8.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.0.8.tar.gz
Horde Project Horde 3.0.3
-
Horde horde-3.0.8.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.0.8.tar.gz
Horde Project Horde 3.0.4 -RC 1
-
Horde horde-3.0.8.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.0.8.tar.gz
Horde Project Horde 3.0.4 -RC 2
-
Horde horde-3.0.8.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.0.8.tar.gz
Horde Project Horde 3.0.4
-
Debian horde3_3.0.4-4sarge3_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/horde3/horde3_3.0.4-4sa rge3_all.deb -
Horde horde-3.0.8.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.0.8.tar.gz
Horde Project Horde 3.0.6
-
Horde horde-3.0.8.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.0.8.tar.gz
Horde Project Horde 3.0.7
-
Horde horde-3.0.8.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.0.8.tar.gz
References
Horde Application Framework Input Validation Vulnerabilities
References:
References:
- [announce] Horde 3.0.8 (final) (Horde Project)
- Horde Homepage (Horde Project)
- SEC Consult Security Advisory < 20051211-0 > (SEC-CONSULT)