Horde '_formvars' Form Input Remote Code Execution Vulnerability
BID:65200
Info
Horde '_formvars' Form Input Remote Code Execution Vulnerability
| Bugtraq ID: | 65200 |
| Class: | Unknown |
| CVE: |
CVE-2014-1691 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2014 12:00AM |
| Updated: | Jun 30 2014 02:52PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Horde Project Horde 3.1.9 Horde Project Horde 3.1.8 Horde Project Horde 3.1.7 Horde Project Horde 3.1.6 Horde Project Horde 3.1.5 Horde Project Horde 3.1.4 Horde Project Horde 3.1.3 Horde Project Horde 3.1.2 Horde Project Horde 3.1.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Horde '_formvars' Form Input Remote Code Execution Vulnerability
Horde is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in denial-of-service conditions.
Horde 3.1.x through versions 5.1.1 are vulnerable; other versions may also be affected.
Horde is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in denial-of-service conditions.
Horde 3.1.x through versions 5.1.1 are vulnerable; other versions may also be affected.
Exploit / POC
Horde '_formvars' Form Input Remote Code Execution Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Horde '_formvars' Form Input Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Horde '_formvars' Form Input Remote Code Execution Vulnerability
References:
References:
- [mms] SECURITY: '_formvars' form input must now be JSON encoded, not �?� (Michael M Slusarz)
- Bug 1059000 - (CVE-2014-1691) CVE-2014-1691 horde: unserializing certain form in (Red Hat Bugzilla)
- Pandora Homepage (Pandora FMS Team)
- Re: Remote code execution in horde < 5.1.1 (Murray McAllister)