First published: Fri Mar 16 2007(Updated: )
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde | =3.0.0 | |
Horde | =3.0.4 | |
Horde | =3.1.3 | |
Horde | =2.0 | |
Horde | =2.2 | |
Horde | =2.2.1 | |
Horde | =2.2.2 | |
Horde | =2.2.3 | |
Horde | =2.2.4 | |
Horde | =2.2.5 | |
Horde | =2.2.6 | |
Horde | =2.2.7 | |
Horde | =2.2.8 | |
Horde | =2.3 | |
Horde | =3.0 | |
Horde | =3.1 | |
Horde | =3.1.2 | |
Horde | =3.2 | |
Horde | =3.2.1 | |
Horde | =3.2.2 | |
Horde | =3.2.3 | |
Horde | =3.2.4 | |
Horde | =3.2.5 | |
Horde | =3.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1474 is considered a moderate severity vulnerability as it allows local users to delete arbitrary files.
To fix CVE-2007-1474, upgrade to Horde Application Framework version 3.1.4 or later.
CVE-2007-1474 affects Horde IMP versions 2.0 to 2.2.8 and 3.0 to 3.2.6, along with Horde Application Framework versions 3.0.0 to 3.1.3.
The impact of CVE-2007-1474 allows local users to potentially gain elevated privileges by deleting arbitrary files.
CVE-2007-1474 can be exploited by local users who have access to the cleanup cron script.