[pkg-horde] Bug#859635: php-horde-crypt: CVE-2017-7413 CVE-2017-7414

Salvatore Bonaccorso carnil at debian.org
Wed Apr 5 12:26:51 UTC 2017


Source: php-horde-crypt
Version: 2.7.5-1
Severity: grave
Tags: security upstream
Justification: user security hole

Hi,

the following vulnerabilities were published for php-horde-crypt.

CVE-2017-7413[0]:
| In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition
| through 5.2.17, OS Command Injection can occur if the attacker is an
| authenticated Horde Webmail user, has PGP features enabled in their
| preferences, and attempts to encrypt an email addressed to a
| maliciously crafted email address.

CVE-2017-7414[1]:
| In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition
| 5.x through 5.2.17, OS Command Injection can occur if the user has PGP
| features enabled in the user's preferences, and has enabled the "Should
| PGP signed messages be automatically verified when viewed?" preference.
| To exploit this vulnerability, an attacker can send a PGP signed email
| (that is maliciously crafted) to the Horde user, who then must either
| view or preview it.

If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-7413
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7413
[1] https://security-tracker.debian.org/tracker/CVE-2017-7414
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7414

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the pkg-horde-hackers mailing list