Horde IMP: Security bypass — GLSA 200802-03

Insufficient checks in Horde may allow a remote attacker to bypass security restrictions.

Affected packages

www-apps/horde-imp on all architectures
Affected versions < 4.1.6
Unaffected versions >= 4.1.6

Background

Horde IMP provides a web-based access to IMAP and POP3 mailboxes.

Description

Ulf Harnhammar, Secunia Research discovered that the "frame" and "frameset" HTML tags are not properly filtered out. He also reported that certain HTTP requests are executed without being checked.

Impact

A remote attacker could entice a user to open a specially crafted HTML e-mail, possibly resulting in the deletion of arbitrary e-mail messages.

Workaround

There is no known workaround at this time.

Resolution

All Horde IMP users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=www-apps/horde-imp-4.1.6"

References

Release date
February 11, 2008

Latest revision
February 11, 2008: 01

Severity
normal

Exploitable
remote

Bugzilla entries