Vulnerability Name:

CVE-2009-0932 (CCN-48286)

Assigned:2009-01-27
Published:2009-01-27
Updated:2011-09-22
Summary:Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-22
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2009-0932

Source: CONFIRM
Type: Vendor Advisory
http://cvs.horde.org/co.php/groupware/docs/groupware/CHANGES?r=1.28.2.5

Source: CONFIRM
Type: Vendor Advisory
http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.413.2.5

Source: CONFIRM
Type: Vendor Advisory
http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.503

Source: CCN
Type: announce Mailing List, Tue Jan 27 15:09:41 UTC 2009
Horde 3.3.3 (final)

Source: MLIST
Type: Vendor Advisory
[announce] 20090127 Horde 3.3.3 (final)

Source: CCN
Type: announce Mailing List, Tue Jan 27 15:17:52 UTC 2009
Horde 3.2.4 (final)

Source: MLIST
Type: Vendor Advisory
[announce] 20090127 Horde 3.2.4 (final)

Source: CCN
Type: announce Mailing List, Tue Jan 27 17:37:00 UTC 2009
Horde Groupware 1.1.5 (final)

Source: MLIST
Type: Vendor Advisory
[announce] 20090127 Horde Groupware 1.1.5 (final)

Source: SUSE
Type: UNKNOWN
SUSE-SR:2009:007

Source: CCN
Type: SA33695
Horde / Horde Groupware Cross-Site Scripting and File Inclusion Vulnerability

Source: SECUNIA
Type: Vendor Advisory
33695

Source: SECUNIA
Type: UNKNOWN
34418

Source: SECUNIA
Type: UNKNOWN
34609

Source: SREASON
Type: UNKNOWN
8077

Source: DEBIAN
Type: DSA-1765
horde3 -- Multiple vulnerabilities

Source: CCN
Type: Horde Web site
The Horde Project

Source: CCN
Type: OSVDB ID: 51887
Horde Multiple Products framework/Image/Image.php Horde_ImageDriver Name Traversal Local File Inclusion

Source: BID
Type: UNKNOWN
33491

Source: CCN
Type: BID-33491
Horde Products Local File Include and Cross Site Scripting Vulnerabilities

Source: XF
Type: UNKNOWN
horde-image-file-include(48286)

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [02-11-2011]

Source: SUSE
Type: SUSE-SR:2009:007
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:debian:horde:3.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:horde:3.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:horde:3.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:debian:horde:3.3:*:*:*:*:*:*:*
  • OR cpe:/a:debian:horde:3.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:horde:3.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:horde_groupware:1.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:debian:horde_groupware:1.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:debian:horde_groupware:1.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:debian:horde_groupware:1.1.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:horde:horde:3.2:*:*:*:*:*:*:*
  • OR cpe:/a:horde:horde:3.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:horde:horde_groupware:1.2:*:*:*:*:*:*:*
  • OR cpe:/a:horde:horde_groupware:1.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:horde:horde_groupware:1.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:horde:horde_groupware:1.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:horde:horde_groupware:1.1.1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20090932
    V
    CVE-2009-0932
    2015-11-16
    oval:org.mitre.oval:def:8165
    P
    DSA-1765 horde3 -- Multiple vulnerabilities
    2014-06-23
    oval:org.mitre.oval:def:13562
    P
    DSA-1765-1 horde3 -- Multiple vulnerabilities
    2014-06-23
    oval:org.debian:def:1765
    V
    Multiple vulnerabilities
    2009-04-08
    BACK
    debian horde 3.2
    debian horde 3.2.2
    debian horde 3.2.3
    debian horde 3.3
    debian horde 3.3.1
    debian horde 3.3.2
    debian horde groupware 1.1.1
    debian horde groupware 1.1.2
    debian horde groupware 1.1.3
    debian horde groupware 1.1.4
    horde horde 3.2
    horde horde 3.2.1
    horde horde groupware 1.2
    horde horde groupware 1.1.3
    horde horde groupware 1.1.4
    horde horde groupware 1.1.2
    horde horde groupware 1.1.1
    debian debian linux 4.0