Multiple Horde Products Security Bypass Vulnerability
BID:27844
Info
Multiple Horde Products Security Bypass Vulnerability
| Bugtraq ID: | 27844 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0807 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2008 12:00AM |
| Updated: | Apr 13 2015 10:17PM |
| Credit: | Peter Paul Elfferich reported this issue. |
| Vulnerable: |
Redhat Fedora 7 Horde Project Groupware Webmail Edition 1.0.4 Horde Project Groupware 1.0.3 Horde Turba Contact Manager 2.1.6 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Horde Project Groupware Webmail Edition 1.0.5 Horde Project Groupware 1.0.4 Horde Turba Contact Manager 2.1.7 |
Discussion
Multiple Horde Products Security Bypass Vulnerability
Horde products are prone to a security-bypass vulnerability.
Attackers can use this issue to bypass certain security restrictions and edit arbitrary contacts in shared and personal address books. This may aid in further attacks.
This issue affects Horde Groupware 1.0.3, Horde Groupware Webmail Edition 1.0.4, and Turba Contact Manager 2.1.6; other versions may also be vulnerable.
Horde products are prone to a security-bypass vulnerability.
Attackers can use this issue to bypass certain security restrictions and edit arbitrary contacts in shared and personal address books. This may aid in further attacks.
This issue affects Horde Groupware 1.0.3, Horde Groupware Webmail Edition 1.0.4, and Turba Contact Manager 2.1.6; other versions may also be vulnerable.
Exploit / POC
Multiple Horde Products Security Bypass Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
Multiple Horde Products Security Bypass Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Horde Project Groupware 1.0.3
Horde Project Groupware Webmail Edition 1.0.4
Horde Turba Contact Manager 2.1.6
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Horde Project Groupware 1.0.3
-
Horde horde-groupware-1.0.4.tar.gz
ftp://ftp.horde.org/pub/horde-groupware/horde-groupware-1.0.4.tar.gz
Horde Project Groupware Webmail Edition 1.0.4
-
Horde horde-webmail-1.0.5.tar.gz
ftp://ftp.horde.org/pub/horde-webmail/horde-webmail-1.0.5.tar.gz
Horde Turba Contact Manager 2.1.6
-
Horde turba-h3-2.1.7.tar.gz
ftp://ftp.horde.org/pub/turba/turba-h3-2.1.7.tar.gz
References
Multiple Horde Products Security Bypass Vulnerability
References:
References:
- #464058 - turba2: Access rights not checked properly (Debian)
- [#6208] [Debian Bug] Access rights not checked properly (Horde Project)
- Diff for groupware/docs/groupware/CHANGES between version 1.17.2.1 and 1.17.2.2 (Horde Project)
- Diff for groupware/docs/webmail/CHANGES between version 1.12.2.1 and 1.12.2.2 (Horde Project)
- Diff for turba/docs/CHANGES between version 1.181.2.114.2.2 and 1.181.2.114.2.4 (Horde Project)
- Pandora Homepage (Pandora FMS Team)