Bug 633030 (CVE-2010-1638)

Summary: CVE-2010-1638 Horde / IMP: Firewall restrictions bypass / internal networs scan via unspecified test script
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NEXTRELEASE QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: j, nb
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-01-30 21:39:56 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jan Lieskovsky 2010-09-12 14:28:21 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1638 to
the following vulnerability:

The IMP plugin in Horde allows remote attackers to bypass firewall 
restrictions and use Horde as a proxy to scan internal networks via 
a crafted request to an unspecified test script. NOTE: this is only 
a vulnerability when the administrator does not follow recommendations 
in the product's installation documentation.

References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1638
[2] http://www.openwall.com/lists/oss-security/2010/05/21/2
[3] http://www.openwall.com/lists/oss-security/2010/05/25/2
[4] http://conference.hitb.org/hitbsecconf2010dxb/materials/D1%20-%20Laurent%20Oudot%20-%20Improving%20the%20Stealthiness%20of%20Web%20Hacking.pdf#page=74

Comment 1 Jan Lieskovsky 2010-09-12 14:32:31 UTC
From reading the CVE description [1] it implies, this is more
a question of proper Horde / IMP plugin configuration, than a
security flaw (and the security implications an attacker could
reach by exploiting this are very low).

But separate Red Hat Bugzilla entry filed for the case, there is
something, what can be done on the Horde IMP side and could
prevent exploitation for any of the installed / used Horde confi-
gurations.

Comment 2 Nick Bebout 2012-01-30 21:39:56 UTC
-> CLOSED NEXTRELEASE

We are upgrading the whole horde and imp stack to the new pear-based version.