FreeBSD : horde-base -- multiple vulnerabilities (ee23aa09-a175-11de-96c0-0011098ad87f)
High Nessus Plugin ID 40979
SynopsisThe remote FreeBSD host is missing a security-related update.
DescriptionThe Horde team reports :
An error within the form library when handling image form fields can be exploited to overwrite arbitrary local files.
An error exists within the MIME Viewer library when rendering unknown text parts. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site if malicious data is viewed.
The preferences system does not properly sanitise numeric preference types. This can be exploited to execute arbitrary HTML and script code in a user's browser session in contact of an affected site.
SolutionUpdate the affected package.