CVE Vulnerabilities

CVE-2009-3236

Published: Sep 17, 2009 | Modified: Jun 18, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW

The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; reuses temporary filenames during the upload process which allows remote attackers, with privileges to write to the address book, to overwrite arbitrary files and execute PHP code via crafted Horde_Form_Type_image form field elements.

Affected Software

Name Vendor Start Version End Version
Application_framework Horde 3.2 (including) 3.2 (including)
Application_framework Horde 3.2.1 (including) 3.2.1 (including)
Application_framework Horde 3.2.2 (including) 3.2.2 (including)
Application_framework Horde 3.2.3 (including) 3.2.3 (including)
Application_framework Horde 3.2.4 (including) 3.2.4 (including)
Application_framework Horde 3.3 (including) 3.3 (including)
Application_framework Horde 3.3.1 (including) 3.3.1 (including)
Application_framework Horde 3.3.2 (including) 3.3.2 (including)
Application_framework Horde 3.3.3 (including) 3.3.3 (including)
Application_framework Horde 3.3.4 (including) 3.3.4 (including)
Groupware Horde 1.1 (including) 1.1 (including)
Groupware Horde 1.1.1 (including) 1.1.1 (including)
Groupware Horde 1.1.2 (including) 1.1.2 (including)
Groupware Horde 1.1.3 (including) 1.1.3 (including)
Groupware Horde 1.1.4 (including) 1.1.4 (including)
Groupware Horde 1.1.5 (including) 1.1.5 (including)
Groupware Horde 1.2 (including) 1.2 (including)
Groupware Horde 1.2-rc1 (including) 1.2-rc1 (including)
Groupware Horde 1.2.1 (including) 1.2.1 (including)
Groupware Horde 1.2.2 (including) 1.2.2 (including)
Groupware Horde 1.2.3 (including) 1.2.3 (including)
Horde3 Ubuntu dapper *
Horde3 Ubuntu hardy *
Horde3 Ubuntu intrepid *
Horde3 Ubuntu jaunty *
Horde3 Ubuntu upstream *

References