PT-2017-17721 · Horde · Horde Groupware Webmail Edition+1

Publicado

2017-04-04

·

Atualizado

2019-10-03

·

CVE-2017-7414

CVSS v3.1

7.5

Alta

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Horde Crypt versions prior to 2.7.6 Horde Groupware Webmail Edition versions 5.x through 5.2.17
Description The issue occurs when a user has PGP features enabled and has chosen to automatically verify PGP signed messages. An attacker can exploit this by sending a maliciously crafted PGP signed email to the user, who must then view or preview the email to trigger the exploit. This can lead to OS Command Injection.
Recommendations For Horde Crypt versions prior to 2.7.6, update to version 2.7.6 or later. For Horde Groupware Webmail Edition versions 5.x through 5.2.17, consider disabling the PGP features or the automatic verification of PGP signed messages until an update is available.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7414
DLA-1398-1

Produtos afetados

Horde Groupware Webmail Edition
Horde Crypt