PublicDate: 2008-03-11 00:44:00 UTC Candidate: CVE-2008-1284 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1284 Description: Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=470640 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_horde3: vendor: http://www.debian.org/security/2008/dsa-1519 other: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=470640 upstream_horde3: released (3.1.7) dapper_horde3: released (3.1.1-1ubuntu0.1) edgy_horde3: pending (3.1.3-1ubuntu0.1) feisty_horde3: released (3.1.3-4ubuntu0.1) gutsy_horde3: released (3.1.4-1ubuntu0.1) hardy_horde3: released (3.1.7-1) devel_horde3: released (3.1.7-1)