Boletines de Vulnerabilidades

DSA-3391 php-horde - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

It was discovered that the web-based administration interface in theHorde Application Framework did not guard against Cross-Site RequestForgery (CSRF) attacks. As a result, other, malicious web pages couldcause Horde applications to perform actions as the Horde user.

More info:

https://www.debian.org/security/2015/dsa-3391

Identificadores estándar

Propiedad Valor
CVE DSA-3391.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-11-06

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT