CVE-2014-1691: Code Injection
Published Apr 1, 2014
·Updated
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the formvars form.
Affected Software
6 affected components
Horde Horde Application Framework<=5.1.0
Horde Horde Application Framework=5.0.0
Horde Horde Application Framework=5.0.1
Horde Horde Application Framework=5.0.2
Horde Horde Application Framework=5.0.3
Horde Horde Application Framework=5.0.4
Remediation
Patch Available
Patch Available
Event History
Apr 1, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1691?
CVE-2014-1691 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2014-1691?
To fix CVE-2014-1691, upgrade Horde Application Framework to version 5.1.1 or later.
3
What type of attack is possible with CVE-2014-1691?
CVE-2014-1691 allows attackers to conduct object injection attacks that can lead to execution of arbitrary PHP code.
4
Which versions of Horde Application Framework are affected by CVE-2014-1691?
CVE-2014-1691 affects Horde Application Framework versions prior to 5.1.1, including 5.0.0 to 5.0.4.
5
Is there a workaround for CVE-2014-1691 if I cannot upgrade?
There are no reliable workarounds for CVE-2014-1691, and upgrading is the recommended solution.