openSUSE 10 Security Update : horde (horde-1868)

This script is Copyright (C) 2007-2014 Tenable Network Security, Inc.


Synopsis :

The remote openSUSE host is missing a security update.

Description :

This update fixes the following two security issues in the Horde
Application Framework :

- CVE-2006-3548: Multiple cross-site scripting (XSS)
vulnerabilities allow remote attackers to inject
arbitrary web script or HTML via a (1) JavaScript URI or
an external (2) http, (3) https, or (4) ftp URI in the
url parameter in services/go.php (aka the dereferrer),
(5) a JavaScript URI in the module parameter in
services/help (aka the help viewer), and (6) the name
parameter in services/problem.php (aka the problem
reporting screen).

- CVE-2006-3549: services/go.php does not properly
restrict its image proxy capability, which allows remote
attackers to perform 'Web tunneling' attacks and use the
server as a proxy via (1) http, (2) https, and (3) ftp
URL in the url parameter, which is requested from the
server.

Solution :

Update the affected horde package.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)

Family: SuSE Local Security Checks

Nessus Plugin ID: 27265 ()

Bugtraq ID:

CVE ID: CVE-2006-3548
CVE-2006-3549

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now