PT-2017-2370 · Horde · Horde Groupware Webmail Edition+1
Published
2017-04-04
·
Updated
2019-10-03
·
CVE-2017-7413
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Horde Crypt versions prior to 2.7.6
Horde Groupware Webmail Edition versions prior to 5.2.18
Description
The issue is related to a lack of input data sanitization, which can lead to OS Command Injection. This can occur if an attacker is an authenticated Horde Webmail user with PGP features enabled in their preferences and attempts to encrypt an email addressed to a maliciously crafted email address.
Recommendations
For Horde Crypt versions prior to 2.7.6, update to version 2.7.6 or later.
For Horde Groupware Webmail Edition versions prior to 5.2.18, update to version 5.2.18 or later.
As a temporary workaround, consider disabling the PGP features in user preferences until a patch is available.
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Horde Groupware Webmail Edition
Horde Crypt