Ingo Procmail Driver Shell Command Execution Vulnerability
BID:20637
Info
Ingo Procmail Driver Shell Command Execution Vulnerability
| Bugtraq ID: | 20637 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5449 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 20 2006 12:00AM |
| Updated: | Jan 15 2007 05:10PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Horde Project Ingo 1.1.1 Horde Project Ingo 1.0.1 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Horde Project Ingo 1.1.2 |
Discussion
Ingo Procmail Driver Shell Command Execution Vulnerability
Ingo is prone to a vulnerability that may permit the execution of arbitrary shell commands. This issue occurs because the Ingo procmail driver fails to properly sanitize user-supplied input.
Exploiting this issue allows attackers to execute arbitrary commands with the privileges of users executing a vulnerable version of the application.
This issue affects version 1.1.1 and earlier.
Ingo is prone to a vulnerability that may permit the execution of arbitrary shell commands. This issue occurs because the Ingo procmail driver fails to properly sanitize user-supplied input.
Exploiting this issue allows attackers to execute arbitrary commands with the privileges of users executing a vulnerable version of the application.
This issue affects version 1.1.1 and earlier.
Exploit / POC
Ingo Procmail Driver Shell Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Ingo Procmail Driver Shell Command Execution Vulnerability
Solution:
The vendor has released version 1.1.2 to address this issue.
Please see the referenced advisories for more information.
Horde Project Ingo 1.0.1
Horde Project Ingo 1.1.1
Solution:
The vendor has released version 1.1.2 to address this issue.
Please see the referenced advisories for more information.
Horde Project Ingo 1.0.1
-
Debian ingo1_1.0.1-1sarge1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/i/ingo1/ingo1_1.0.1-1sarg e1_all.deb
Horde Project Ingo 1.1.1
-
Horde Horde Ingo 1.1.2
http://lists.horde.org/archives/announce/2006/000296.html
References
Ingo Procmail Driver Shell Command Execution Vulnerability
References:
References: