Description: | Description: The remote host is missing an update to horde announced via advisory FEDORA-2010-5563.
Update Information:
Upgrade to 3.3.6 - Fixes a lot of security bugs
References:
[ 1 ] Bug #549506 - CVE-2009-3701 horde: PHP_SELF XSS vulnerabilities https://bugzilla.redhat.com/show_bug.cgi?id=549506 [ 2 ] Bug #549516 - CVE-2009-4363 horde: XSS vulnerability via data: URIs https://bugzilla.redhat.com/show_bug.cgi?id=549516 [ 3 ] Bug #523401 - CVE-2009-3236 Horde: Improper validation of image form fields (local files overwrite) https://bugzilla.redhat.com/show_bug.cgi?id=523401 [ 4 ] Bug #523407 - CVE-2009-3237 Horde: XSS in number type preferences and in MIME rendering https://bugzilla.redhat.com/show_bug.cgi?id=523407 [ 5 ] Bug #490932 - CVE-2009-0931 CVE-2009-0932 horde: XSS vulnerability and directory traversal vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=490932 [ 6 ] Bug #461886 - CVE-2008-3823 horde: XSS via filename of MIME attachments (oCERT-2008-012) https://bugzilla.redhat.com/show_bug.cgi?id=461886 [ 7 ] Bug #461887 - CVE-2008-3824 horde: XSS via unescaped '/' characters (oCERT-2008-012) https://bugzilla.redhat.com/show_bug.cgi?id=461887 [ 8 ] Bug #480818 - CVE-2008-5917 horde: IE-specific XSS via image style attribute https://bugzilla.redhat.com/show_bug.cgi?id=480818
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update horde' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2010-5563
Risk factor : High
CVSS Score: 6.4
|