Horde: Multiple vulnerabilities Multiple vulnerabilities in the Horde Application Framework can allow for arbitrary files to be overwritten and cross-site scripting attacks. horde horde-webmail horde-groupware 2009-11-06 2009-11-06 285052 remote 3.3.5 3.3.5 1.2.4 1.2.4 1.2.4 1.2.4

Horde is a web application framework written in PHP.

Multiple vulnerabilities have been discovered in Horde:

A remote authenticated attacker could exploit these vulnerabilities to overwrite arbitrary files on the server, provided that the user has write permissions. A remote authenticated attacker could conduct Cross-Site Scripting attacks.

There is no known workaround at this time.

All Horde users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-apps/horde-3.3.5"

All Horde webmail users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-apps/horde-webmail-1.2.4"

All Horde groupware users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-apps/horde-groupware-1.2.4"
CVE-2009-3236 CVE-2009-3237 keytoaster chainsaw a3li