CVE-2009-3236: Medium severity horde groupware webmail edition vulnerability
The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; reuses temporary filenames during the upload process which allows remote attackers, with privileges to write to the address book, to overwrite arbitrary files and execute PHP code via crafted HordeFormTypeimage form field elements.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3236?
CVE-2009-3236 is considered a medium severity vulnerability due to its impact on file upload processes.
How do I fix CVE-2009-3236?
To fix CVE-2009-3236, update your Horde Application Framework and Groupware to version 3.2.5, 3.3.5, 1.1.6, or 1.2.4 or later.
What systems are affected by CVE-2009-3236?
CVE-2009-3236 affects Horde Application Framework versions 3.2.x and 3.3.x, along with Groupware versions 1.1.x and 1.2.x.
What type of attack can exploit CVE-2009-3236?
CVE-2009-3236 can be exploited by remote attackers through the reuse of temporary filenames during file uploads.
Is there a patch available for CVE-2009-3236?
Yes, a patch is available in the form of upgrades to the specified versions of affected Horde software.