First published: Thu Dec 05 2013(Updated: )
CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | =3.1 | |
Cybozu Garoon | =3.1-sp1 | |
Cybozu Garoon | =3.1-sp2 | |
Cybozu Garoon | =3.1-sp3 | |
Cybozu Garoon | =3.5 | |
Cybozu Garoon | =3.5-sp1 | |
Cybozu Garoon | =3.5-sp2 | |
Cybozu Garoon | =3.5-sp3 | |
Cybozu Garoon | =3.5-sp4 | |
Cybozu Garoon | =3.5-sp5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-6003 is classified as medium risk due to potential CRLF injection in email headers.
To fix CVE-2013-6003, upgrade Cybozu Garoon to the latest version that addresses this vulnerability.
CVE-2013-6003 affects users of Cybozu Garoon versions 3.1 through 3.5 SP5.
CVE-2013-6003 allows remote authenticated users to inject arbitrary email headers, possibly leading to spoofing or phishing attacks.
Yes, CVE-2013-6003 can be exploited remotely by authenticated users when Phone Messages forwarding is enabled.