CVE-2008-0807: Medium severity debian linux vulnerability
It was reported that turba does not properly check permissions on address books, allowing users to modify addresses in other users' address books. This problem affects both shared and non-shared address books. Knowing (or guessing) the objectid seems to be sufficient to allow modification of other users' addresses.
More information can be found in Debian bug report, which also contains some proposed patches: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058
Upstream bug report: http://bugs.horde.org/ticket/?id=6208
Other sources
lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified objectid parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0807?
CVE-2008-0807 has high severity due to its potential for unauthorized modification of user address books.
How do I fix CVE-2008-0807?
To fix CVE-2008-0807, ensure that proper permission checks are implemented for accessing address books.
Which software is affected by CVE-2008-0807?
CVE-2008-0807 affects Horde Turba Contact Manager versions prior to 2.1.6.
Can CVE-2008-0807 affect shared address books?
Yes, CVE-2008-0807 affects both shared and non-shared address books, allowing unauthorized modifications.
What can happen if CVE-2008-0807 is exploited?
If exploited, CVE-2008-0807 could allow unauthorized users to modify or delete addresses in other users' address books.