Boletines de Vulnerabilidades

DSA-3391 php-horde - security update

   
Software afectado Debian
 
It was discovered that the web-based administration interface in theHorde Application Framework did not guard against Cross-Site RequestForgery (CSRF) attacks. As a result, other, malicious web pages couldcause Horde applications to perform actions as the Horde user.

More info:

https://www.debian.org/security/2015/dsa-3391