LWN.net Logo

horde3: file execution and disclosure via directory traversal

Package(s):horde3 CVE #(s):CVE-2008-1284
Created:March 17, 2008 Updated:May 6, 2008
Description:

From the CVE entry:

Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name.

Alerts:
Debian DSA-1519-1 2008-03-15
Fedora FEDORA-2008-2406 2008-03-13
Fedora FEDORA-2008-2362 2008-03-13
Gentoo 200805-01 2008-05-05

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.