Horde Products Multiple Unspecified Security Bypass Vulnerabilities
BID:27217
Info
Horde Products Multiple Unspecified Security Bypass Vulnerabilities
| Bugtraq ID: | 27217 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-7219 CVE-2008-7218 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | The vendor disclosed these issues. |
| Vulnerable: |
Red Hat Fedora 7 Horde Project Kronolith 2.1.6 Horde Project Horde 3.1.5 Horde Project Groupware Webmail Edition 1.0.3 Horde Project Groupware 1.0.2 Horde Turba Contact Manager 2.1.5 Horde Nag 2.1.3 Horde Mnemo 2.1.1 |
| Not Vulnerable: |
Horde Project Kronolith 2.1.7 Horde Project Horde 3.1.6 Horde Project Groupware Webmail Edition 1.0.4 Horde Project Groupware 1.0.3 Horde Turba Contact Manager 2.1.6 Horde Nag 2.1.4 Horde Mnemo 2.1.2 |
Discussion
Horde Products Multiple Unspecified Security Bypass Vulnerabilities
Horde products are prone to multiple unspecified security-bypass vulnerabilities.
Attackers can use these issues to bypass certain security restrictions and perform unauthorized actions; other attacks may also be possible.
These issues affect Horde 3.1.5, Mnemo 2.1.1, Nag 2.1.3, Kronolith 2.1.6, Turba 2.1.5, Horde Groupware Webmail Edition 1.0.3, and Horde Groupware 1.0.2; other versions may also be vulnerable.
Very little is known about these issues at this time. We will update this BID as more information emerges.
Horde products are prone to multiple unspecified security-bypass vulnerabilities.
Attackers can use these issues to bypass certain security restrictions and perform unauthorized actions; other attacks may also be possible.
These issues affect Horde 3.1.5, Mnemo 2.1.1, Nag 2.1.3, Kronolith 2.1.6, Turba 2.1.5, Horde Groupware Webmail Edition 1.0.3, and Horde Groupware 1.0.2; other versions may also be vulnerable.
Very little is known about these issues at this time. We will update this BID as more information emerges.
Exploit / POC
Horde Products Multiple Unspecified Security Bypass Vulnerabilities
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
An attacker could likely use a browser to exploit these issues.
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
An attacker could likely use a browser to exploit these issues.
Solution / Fix
Horde Products Multiple Unspecified Security Bypass Vulnerabilities
Solution:
The vendor released updates to address these issues. Please see the references for more information.
Horde Project Groupware 1.0.2
Horde Project Groupware Webmail Edition 1.0.3
Horde Project Mnemo 2.1.1
Horde Nag 2.1.3
Horde Turba Contact Manager 2.1.5
Horde Project Kronolith 2.1.6
Horde Project Horde 3.1.5
Solution:
The vendor released updates to address these issues. Please see the references for more information.
Horde Project Groupware 1.0.2
-
Horde horde-groupware-1.0.3.tar.gz
ftp://ftp.horde.org/pub/horde-groupware/horde-groupware-1.0.3.tar.gz
Horde Project Groupware Webmail Edition 1.0.3
-
Horde horde-webmail-1.0.4.tar.gz
ftp://ftp.horde.org/pub/horde-webmail/
Horde Project Mnemo 2.1.1
-
Horde mnemo-h3-2.1.2.tar.gz
ftp://ftp.horde.org/pub/mnemo/mnemo-h3-2.1.2.tar.gz
Horde Nag 2.1.3
-
Horde nag-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/nag/nag-h3-2.1.4.tar.gz
Horde Turba Contact Manager 2.1.5
-
Horde turba-h3-2.1.6.tar.gz
ftp://ftp.horde.org/pub/turba/turba-h3-2.1.6.tar.gz
Horde Project Kronolith 2.1.6
-
Horde kronolith-h3-2.1.7.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.7.tar.gz
Horde Project Horde 3.1.5
-
Horde horde-3.1.6.tar.gz
ftp://ftp.horde.org/pub/horde/horde-3.1.6.tar.gz
References
Horde Products Multiple Unspecified Security Bypass Vulnerabilities
References:
References:
- Pandora Homepage (Pandora FMS Team)