Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Imp |
Horde |
2.0 |
2.0 |
Imp |
Horde |
2.2 |
2.2 |
Imp |
Horde |
2.2.1 |
2.2.1 |
Imp |
Horde |
2.2.2 |
2.2.2 |
Imp |
Horde |
2.2.3 |
2.2.3 |
Imp |
Horde |
* |
2.2.4 |
References