CVE-2013-6003: Input Validation
Published Dec 5, 2013
·Updated
CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers via unspecified vectors.
Affected Software
10 affected components
Cybozu Garoon=3.1
Cybozu Garoon=3.1-sp1
Cybozu Garoon=3.1-sp2
Cybozu Garoon=3.1-sp3
Cybozu Garoon=3.5
Cybozu Garoon=3.5-sp1
Cybozu Garoon=3.5-sp2
Cybozu Garoon=3.5-sp3
Cybozu Garoon=3.5-sp4
Cybozu Garoon=3.5-sp5
Event History
Dec 5, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-6003?
The severity of CVE-2013-6003 is classified as medium risk due to potential CRLF injection in email headers.
2
How do I fix CVE-2013-6003?
To fix CVE-2013-6003, upgrade Cybozu Garoon to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2013-6003?
CVE-2013-6003 affects users of Cybozu Garoon versions 3.1 through 3.5 SP5.
4
What is the impact of CVE-2013-6003?
CVE-2013-6003 allows remote authenticated users to inject arbitrary email headers, possibly leading to spoofing or phishing attacks.
5
Can CVE-2013-6003 be exploited remotely?
Yes, CVE-2013-6003 can be exploited remotely by authenticated users when Phone Messages forwarding is enabled.