CVE-2008-0807: Medium severity debian linux vulnerability

Published Feb 8, 2008
·
Updated

It was reported that turba does not properly check permissions on address books, allowing users to modify addresses in other users' address books. This problem affects both shared and non-shared address books. Knowing (or guessing) the objectid seems to be sufficient to allow modification of other users' addresses.

More information can be found in Debian bug report, which also contains some proposed patches: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464058

Upstream bug report: http://bugs.horde.org/ticket/?id=6208

Other sources

lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified objectid parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.

Affected Software

17 affected componentsFixes available
redhat/3.1.6<1.
1.
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Debian Debian Linux=4.0
Horde Groupware=1.0.3
Horde Groupware Webmail Edition=1.0.4
Horde Turba Contact Manager=2.1.6

Event History

Feb 19, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
01:00 AM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2008-0807?

CVE-2008-0807 has high severity due to its potential for unauthorized modification of user address books.

2

How do I fix CVE-2008-0807?

To fix CVE-2008-0807, ensure that proper permission checks are implemented for accessing address books.

3

Which software is affected by CVE-2008-0807?

CVE-2008-0807 affects Horde Turba Contact Manager versions prior to 2.1.6.

4

Can CVE-2008-0807 affect shared address books?

Yes, CVE-2008-0807 affects both shared and non-shared address books, allowing unauthorized modifications.

5

What can happen if CVE-2008-0807 is exploited?

If exploited, CVE-2008-0807 could allow unauthorized users to modify or delete addresses in other users' address books.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203