CVE-2017-7414 Information
Feb 14, 2021
cve
Description
In Horde_Crypt before 2.7.6 as used in Horde Groupware Webmail Edition 5.x through 5.2.17 OS Command Injection can occur if the user has PGP features enabled in the user’s preferences and has enabled the \Should PGP signed messages be automatically verified when viewed?\ preference. To exploit this vulnerability an attacker can send a PGP signed email (that is maliciously crafted) to the Horde user who then must either view or preview it.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://lists.debian.org/debian-lts-announce/2018/06/msg00006.html https://lists.horde.org/archives/horde/Week-of-Mon-20170403/056767.html
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.5
Share on: