PT-2010-2227 · Horde · Horde Imp
Publicado
2010-01-29
·
Atualizado
2017-08-17
·
CVE-2010-0463
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Horde IMP versions 4.3.6 and earlier
Description
The issue makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests, as the software does not request the web browser to avoid DNS prefetching of domain names contained in e-mail messages.
Recommendations
For versions 4.3.6 and earlier, consider configuring the web browser to avoid DNS prefetching of domain names contained in e-mail messages as a temporary workaround until a patch is available.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Horde Imp