Horde IMP Message Attachment Symbolic Link Vulnerability
BID:2805
Info
Horde IMP Message Attachment Symbolic Link Vulnerability
| Bugtraq ID: | 2805 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2001 12:00AM |
| Updated: | May 31 2001 12:00AM |
| Credit: | Reported to bugtraq by Jarno Huuskonen <[email protected]> on May 31, 2001. |
| Vulnerable: |
Horde Project IMP 2.2.4 Horde Project IMP 2.2.3 Horde Project IMP 2.2.2 Horde Project IMP 2.2.1 Horde Project IMP 2.2 Horde Project IMP 2.0 |
| Not Vulnerable: |
Horde Project IMP 2.2.5 |
Exploit / POC
Horde IMP Message Attachment Symbolic Link Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Horde IMP Message Attachment Symbolic Link Vulnerability
Solution:
(courtesy Jarno Huuskonen <[email protected]>)
---
Solution:
Upgrade to imp-2.2.5 and use the 'upload_tmp_dir' directive (php.ini) to define a directory where uploaded files should go (see imp/docs/SECURITY for more information).
Note: Imp-2.2.5 uses the PHP tempnam function for creating temporary files. With PHP versions earlier than 4.0.3? the tempnam function doesn't use mkstemp (so it has a race condition) so upgrading to PHP-4.0.5 or patching PHP-3.0.18 to use mkstemp is advisable[4].
---
Horde Project IMP 2.0
Horde Project IMP 2.2
Horde Project IMP 2.2.1
Horde Project IMP 2.2.2
Horde Project IMP 2.2.3
Horde Project IMP 2.2.4
Solution:
(courtesy Jarno Huuskonen <[email protected]>)
---
Solution:
Upgrade to imp-2.2.5 and use the 'upload_tmp_dir' directive (php.ini) to define a directory where uploaded files should go (see imp/docs/SECURITY for more information).
Note: Imp-2.2.5 uses the PHP tempnam function for creating temporary files. With PHP versions earlier than 4.0.3? the tempnam function doesn't use mkstemp (so it has a race condition) so upgrading to PHP-4.0.5 or patching PHP-3.0.18 to use mkstemp is advisable[4].
---
Horde Project IMP 2.0
-
Horde imp-2.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/tarballs/imp-2.2.5.tar.gz
Horde Project IMP 2.2
-
Horde imp-2.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/tarballs/imp-2.2.5.tar.gz
Horde Project IMP 2.2.1
-
Horde imp-2.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/tarballs/imp-2.2.5.tar.gz
Horde Project IMP 2.2.2
-
Horde imp-2.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/tarballs/imp-2.2.5.tar.gz
Horde Project IMP 2.2.3
-
Horde imp-2.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/tarballs/imp-2.2.5.tar.gz
Horde Project IMP 2.2.4
-
Horde imp-2.2.5.tar.gz
ftp://ftp.horde.org/pub/imp/tarballs/imp-2.2.5.tar.gz
References
Horde IMP Message Attachment Symbolic Link Vulnerability
References:
References: