Executive Summary
Summary | |
---|---|
Title | New horde3 packages fix several vulnerabilities |
Informations | |||
---|---|---|---|
Name | DSA-1765 | First vendor Publication | 2009-04-08 |
Vendor | Debian | Last vendor Modification | 2009-04-08 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 6.4 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several vulnerabilities have been found in horde3, the horde web application framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0932 Gunnar Wrobel discovered a directory traversal vulnerability, which allows attackers to include and execute arbitrary local files via the driver parameter in Horde_Image. CVE-2008-3330 It was discovered that an attacker could perform a cross-site scripting attack via the contact name, which allows attackers to inject arbitrary html code. This requires that the attacker has access to create contacts. CVE-2008-5917 It was discovered that the horde XSS filter is prone to a cross-site scripting attack, which allows attackers to inject arbitrary html code. This is only exploitable when Internet Explorer is used. For the oldstable distribution (etch), these problems have been fixed in version 3.1.3-4etch5. For the stable distribution (lenny), these problems have been fixed in version 3.2.2+debian0-2, which was already included in the lenny release. For the testing distribution (squeeze) and the unstable distribution (sid), these problems have been fixed in version 3.2.2+debian0-2. We recommend that you upgrade your horde3 packages. |
Original Source
Url : http://www.debian.org/security/2009/dsa-1765 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-251 | Local Code Inclusion |
CAPEC-252 | PHP Local File Inclusion |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
67 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
33 % | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:13562 | |||
Oval ID: | oval:org.mitre.oval:def:13562 | ||
Title: | DSA-1765-1 horde3 -- Multiple vulnerabilities | ||
Description: | Several vulnerabilities have been found in horde3, the horde web application framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0932 Gunnar Wrobel discovered a directory traversal vulnerability, which allows attackers to include and execute arbitrary local files via the driver parameter in Horde_Image. CVE-2008-3330 It was discovered that an attacker could perform a cross-site scripting attack via the contact name, which allows attackers to inject arbitrary html code. This requires that the attacker has access to create contacts. CVE-2008-5917 It was discovered that the horde XSS filter is prone to a cross-site scripting attack, which allows attackers to inject arbitrary html code. This is only exploitable when Internet Explorer is used. For the oldstable distribution, these problems have been fixed in version 3.1.3-4etch5. For the stable distribution, these problems have been fixed in version 3.2.2+debian0-2, which was already included in the lenny release. For the testing distribution and the unstable distribution , these problems have been fixed in version 3.2.2+debian0-2. We recommend that you upgrade your horde3 packages. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1765-1 CVE-2009-0932 CVE-2008-3330 CVE-2008-5917 | Version: | 5 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | horde3 |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:8165 | |||
Oval ID: | oval:org.mitre.oval:def:8165 | ||
Title: | DSA-1765 horde3 -- Multiple vulnerabilities | ||
Description: | Several vulnerabilities have been found in horde3, the horde web application framework. The Common Vulnerabilities and Exposures project identifies the following problems: Gunnar Wrobel discovered a directory traversal vulnerability, which allows attackers to include and execute arbitrary local files via the driver parameter in Horde_Image. It was discovered that an attacker could perform a cross-site scripting attack via the contact name, which allows attackers to inject arbitrary html code. This requires that the attacker has access to create contacts. It was discovered that the horde XSS filter is prone to a cross-site scripting attack, which allows attackers to inject arbitrary html code. This is only exploitable when Internet Explorer is used. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1765 CVE-2009-0932 CVE-2008-3330 CVE-2008-5917 | Version: | 3 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | horde3 |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 6 | |
Application | 4 | |
Application | 1 | |
Application | 2 |
ExploitDB Exploits
id | Description |
---|---|
2011-02-11 | Horde Horde_Image::factory driver Argument Local File Inclusion |
OpenVAS Exploits
Date | Description |
---|---|
2011-02-17 | Name : Horde Products Local File Inclusion Vulnerability File : nvt/gb_horde_lfi_vuln.nasl |
2010-04-06 | Name : Fedora Update for horde FEDORA-2010-5483 File : nvt/gb_fedora_2010_5483_horde_fc11.nasl |
2010-04-06 | Name : Fedora Update for horde FEDORA-2010-5520 File : nvt/gb_fedora_2010_5520_horde_fc12.nasl |
2009-09-15 | Name : Gentoo Security Advisory GLSA 200909-14 (horde horde-imp horde-passwd) File : nvt/glsa_200909_14.nasl |
2009-04-15 | Name : Debian Security Advisory DSA 1765-1 (horde3) File : nvt/deb_1765_1.nasl |
2009-04-10 | Name : Horde Turba 'services/obrowser/index.php' HTML Injection Vulnerability File : nvt/horde_29745.nasl |
2009-04-10 | Name : Horde XSS Filter Cross Site Scripting Vulnerability File : nvt/horde_33367.nasl |
2009-04-10 | Name : Horde Products Local File Include and Cross Site Scripting Vulnerabilities File : nvt/horde_33491.nasl |
2009-03-31 | Name : SuSE Security Summary SUSE-SR:2009:007 File : nvt/suse_sr_2009_007.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
53540 | Horde Application Framework framework/Text_Filter/Filter/xss.php Style Attrib... |
51887 | Horde Multiple Products framework/Image/Image.php Horde_ImageDriver Name Trav... |
46174 | Horde Turba services/obrowser/index.php Contact View XSS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-07-01 | Name : The remote Fedora host is missing a security update. File : fedora_2010-5483.nasl - Type : ACT_GATHER_INFO |
2010-07-01 | Name : The remote Fedora host is missing a security update. File : fedora_2010-5520.nasl - Type : ACT_GATHER_INFO |
2010-07-01 | Name : The remote Fedora host is missing a security update. File : fedora_2010-5563.nasl - Type : ACT_GATHER_INFO |
2009-09-14 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200909-14.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_horde-081119.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_horde-090319.nasl - Type : ACT_GATHER_INFO |
2009-04-09 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1765.nasl - Type : ACT_GATHER_INFO |
2009-03-24 | Name : The remote openSUSE host is missing a security update. File : suse_horde-6099.nasl - Type : ACT_GATHER_INFO |
2009-01-29 | Name : The remote web server contains a PHP application that is susceptible to a loc... File : horde_image_driver_type_lfi.nasl - Type : ACT_ATTACK |
2008-11-25 | Name : The remote openSUSE host is missing a security update. File : suse_horde-5791.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:28:21 |
|