CVE Vulnerabilities

CVE-2007-1474

Published: Mar 16, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.

Affected Software

Name Vendor Start Version End Version
Horde_application_framework Horde 3.0.0 (including) 3.0.0 (including)
Horde_application_framework Horde 3.0.4 (including) 3.0.4 (including)
Horde_application_framework Horde 3.1.3 (including) 3.1.3 (including)
Imp Horde 2.0 (including) 2.0 (including)
Imp Horde 2.2 (including) 2.2 (including)
Imp Horde 2.2.1 (including) 2.2.1 (including)
Imp Horde 2.2.2 (including) 2.2.2 (including)
Imp Horde 2.2.3 (including) 2.2.3 (including)
Imp Horde 2.2.4 (including) 2.2.4 (including)
Imp Horde 2.2.5 (including) 2.2.5 (including)
Imp Horde 2.2.6 (including) 2.2.6 (including)
Imp Horde 2.2.7 (including) 2.2.7 (including)
Imp Horde 2.2.8 (including) 2.2.8 (including)
Imp Horde 2.3 (including) 2.3 (including)
Imp Horde 3.0 (including) 3.0 (including)
Imp Horde 3.1 (including) 3.1 (including)
Imp Horde 3.1.2 (including) 3.1.2 (including)
Imp Horde 3.2 (including) 3.2 (including)
Imp Horde 3.2.1 (including) 3.2.1 (including)
Imp Horde 3.2.2 (including) 3.2.2 (including)
Imp Horde 3.2.3 (including) 3.2.3 (including)
Imp Horde 3.2.4 (including) 3.2.4 (including)
Imp Horde 3.2.5 (including) 3.2.5 (including)
Imp Horde 3.2.6 (including) 3.2.6 (including)
Horde3 Ubuntu dapper *
Horde3 Ubuntu devel *
Horde3 Ubuntu edgy *
Horde3 Ubuntu feisty *
Horde3 Ubuntu gutsy *
Horde3 Ubuntu hardy *
Horde3 Ubuntu intrepid *
Horde3 Ubuntu jaunty *
Horde3 Ubuntu karmic *
Horde3 Ubuntu upstream *

References