Vulnerability CVE-2017-14650


Published: 2017-09-21

Description:
A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "convert" utility. It's not exploitable through any Horde application, because the code path to the vulnerability is not used by any Horde code. Custom applications using the Horde_Image library might be affected. This vulnerability affects all versions of Horde_Image from 2.0.0 to 2.5.1, and is fixed in 2.5.2. The problem is missing input validation of the index field in _raw() during construction of an ImageMagick command line.

Type:

CWE-20

(Improper Input Validation)

Vendor: IBM
Product: Tririga application platform 
Version:
3.5.3
3.5.2.3
3.5.2.2
3.5.2.1
3.5.2
3.5.1.3
3.5.1.2
3.5.1.1
3.5.1
3.5.0.2
3.5.0.1
3.5.0.0
3.4.2.5
3.4.2.4
3.4.2.3
3.4.2.2
3.4.2.1
3.4.2.0
3.4.1.3
3.4.1.2
3.4.1.1
3.4.1.0
3.4.0.1
3.4.0.0
3.3.2.5
3.3.2.4
3.3.2.3
3.3.2.2
3.3.2.1
3.3.2.0
3.3.1.3
3.3.1.2
3.3.1.1
3.3.1.0
3.3.0.2
3.3.0.1
3.3.0.0
Vendor: Horde
Product: Horde image api 
Version:
2.5.1
2.5.0
2.4.1
2.4.0
2.3.6
2.3.5
2.3.4
2.3.3
2.3.2
2.3.1
2.3.0
2.2.0
2.1.0
2.0.9
2.0.8
2.0.7
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

 References:
http://www.openwall.com/lists/oss-security/2017/09/21/4
https://github.com/horde/horde/commit/eb3afd14c22c77ae0d29e2848f5ac726ef6e7c5b
https://marc.info/?l=horde-announce&m=150600299528079&w=2
https://www.debian.org/security/2018/dsa-4276

Related CVE
CVE-2013-6364
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
CVE-2013-6275
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
CVE-2019-9858
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Horde_Form_Type_image method onSubmit() is called on uploads, it invokes t...
CVE-2017-17689
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
CVE-2017-17688
** DISPUTED ** The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle th...
CVE-2017-17781
In Horde Groupware through 5.2.22, SQL Injection exists via the group parameter to /services/prefs.php or the homePostalCode parameter to /turba/search.php.
CVE-2017-16908
In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CVE-2015-7984 CSRF protection mechanism can then be...
CVE-2017-16906
In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action.

Copyright 2019, cxsecurity.com

 

Back to Top