PT-2017-2370 · Horde · Horde Groupware Webmail Edition+1

Published

2017-04-04

·

Updated

2019-10-03

·

CVE-2017-7413

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Horde Crypt versions prior to 2.7.6 Horde Groupware Webmail Edition versions prior to 5.2.18
Description The issue is related to a lack of input data sanitization, which can lead to OS Command Injection. This can occur if an attacker is an authenticated Horde Webmail user with PGP features enabled in their preferences and attempts to encrypt an email addressed to a maliciously crafted email address.
Recommendations For Horde Crypt versions prior to 2.7.6, update to version 2.7.6 or later. For Horde Groupware Webmail Edition versions prior to 5.2.18, update to version 5.2.18 or later. As a temporary workaround, consider disabling the PGP features in user preferences until a patch is available.

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01570
CVE-2017-7413
DLA-1398-1

Affected Products

Horde Groupware Webmail Edition
Horde Crypt