CVE-2009-3236

NameCVE-2009-3236
DescriptionThe form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; reuses temporary filenames during the upload process which allows remote attackers, with privileges to write to the address book, to overwrite arbitrary files and execute PHP code via crafted Horde_Form_Type_image form field elements.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1897-1
Debian Bugs547318

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
horde3sourceetch3.1.3-4etch6DSA-1897-1
horde3sourcelenny3.2.2+debian0-2+lenny1DSA-1897-1
horde3source(unstable)3.3.5+debian0-1medium547318

Search for package or bug name: Reporting problems