Bug 633030 (CVE-2010-1638)
| Summary: | CVE-2010-1638 Horde / IMP: Firewall restrictions bypass / internal networs scan via unspecified test script | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED NEXTRELEASE | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | j, nb |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2012-01-30 21:39:56 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Jan Lieskovsky
2010-09-12 14:28:21 UTC
From reading the CVE description [1] it implies, this is more a question of proper Horde / IMP plugin configuration, than a security flaw (and the security implications an attacker could reach by exploiting this are very low). But separate Red Hat Bugzilla entry filed for the case, there is something, what can be done on the Horde IMP side and could prevent exploitation for any of the installed / used Horde confi- gurations. -> CLOSED NEXTRELEASE We are upgrading the whole horde and imp stack to the new pear-based version. |