FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

horde-base -- multiple vulnerabilities

Affected packages
horde-base < 3.3.5

Details

VuXML ID ee23aa09-a175-11de-96c0-0011098ad87f
Discovery 2009-05-28
Entry 2009-09-14
Modified 2009-09-22

The Horde team reports:

An error within the form library when handling image form fields can be exploited to overwrite arbitrary local files.

An error exists within the MIME Viewer library when rendering unknown text parts. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site if malicious data is viewed.

The preferences system does not properly sanitise numeric preference types. This can be exploited to execute arbitrary HTML and script code in a user's browser session in contact of an affected site.

References

URL http://bugs.horde.org/ticket/?id=8311
URL http://bugs.horde.org/ticket/?id=8399
URL http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.558&r2=1.515.2.559
URL http://secunia.com/advisories/36665/