Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Mar 2004
    Posts
    16

    Default horde vulnerability

    There's a vulnerability in Horde that appears to allow remote code-execution. I haven't looked closely enough at it yet to determine whether it requires a user be logged in and is thus less of a threat (I think that's the case due to the way cpanel wraps horde and requires a login first, but I'm not positive), but either way wanted to post it here first.

    It's been given CVE number 2006-1491, and the appropriate diff is available on the horde cvs page. FYI, it's not actually line 54 in the version of horde running on the latest stable of cpanel (assuming I'm running what I think I'm running), but rather, was in line 56.

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jun 2003
    Posts
    647

    Default

    Horde has been updated in both CURRENT and EDGE. The updates should make it down to the STABLE tree within the week.

  3. #3
    Member
    Join Date
    Mar 2004
    Posts
    16

    Default

    Thanks! Quick turn around. Kudos to the cpanel team.

Similar Threads & Tags
Similar threads

  1. Horde Vulnerability
    By QuetzlcoatlBlue in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-23-2009, 02:50 PM
  2. New IE Vulnerability
    By markb14391 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-16-2008, 07:36 PM
  3. Possible Horde Vulnerability
    By vince512 in forum cPanel and WHM Discussions
    Replies: 61
    Last Post: 03-31-2008, 10:14 AM
  4. SECURITY ALERT: Horde arbitrary file inclusion vulnerability
    By ericgregory in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-06-2008, 11:10 PM
  5. SECURITY ALERT: Horde arbitrary file inclusion vulnerability
    By ericgregory in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-06-2008, 11:10 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube