CVE-2017-7413: OS Command Injection
In HordeCrypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has PGP features enabled in their preferences, and attempts to encrypt an email addressed to a maliciously crafted email address.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Horde_Cryptto a version that resolves this vulnerability.Fixed in 2.7.6
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7413?
CVE-2017-7413 is classified as a high severity vulnerability due to its potential exploitation through OS command injection.
How do I fix CVE-2017-7413?
To fix CVE-2017-7413, upgrade Horde_Crypt to version 2.7.6 or later and ensure your Horde Groupware Webmail Edition is updated beyond version 5.2.17.
Who is affected by CVE-2017-7413?
CVE-2017-7413 affects authenticated Horde Webmail users who have PGP features enabled in their preferences.
What types of attacks are possible with CVE-2017-7413?
CVE-2017-7413 allows attackers to execute OS commands on the server by exploiting the email encryption feature.
What are the implications of CVE-2017-7413?
Exploiting CVE-2017-7413 can lead to unauthorized access and control over the server hosting the affected Horde Groupware installation.