Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Gentoo: 200802-03 Normal: Horde IMP Security Bypass Issue

gentoo
Calendar Grey February 11, 2008
Scroller Gentoo
Gentoo Advisory GLSA-202105-12 details a vulnerability in WordPress that could allow unauthorized access. Immediate update suggested.
Insufficient checks in Horde may allow a remote attacker to bypass security restrictions.

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200802-03
                                            https://security.gentoo.org/

Severity: Normal Title: Horde IMP: Security bypass Date: February 11, 2008 Bugs: #205377 ID: 200802-03

Synopsis ======= Insufficient checks in Horde may allow a remote attacker to bypass security restrictions.
Background ========= Horde IMP provides a web-based access to IMAP and POP3 mailboxes.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/horde-imp < 4.1.6 >= 4.1.6
========== Ulf Harnhammar, Secunia Research discovered that the "frame" and "frameset" HTML tags are not properly filtered out. He also reported that certain HTT...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround