Candidate: CVE-2014-1691 PublicDate: 2014-04-01 15:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1691 https://github.com/horde/horde/commit/da6afc7e9f4e290f782eca9dbca794f772caccb3 https://github.com/horde/horde/commit/acf67ab4a633037849aca9e4a7592465b999ad93 is also required Description: The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_php-horde-util: upstream_php-horde-util: released (2.3.0-1) lucid_php-horde-util: DNE precise_php-horde-util: DNE precise/esm_php-horde-util: DNE quantal_php-horde-util: ignored (reached end-of-life) saucy_php-horde-util: ignored (reached end-of-life) trusty_php-horde-util: not-affected (2.3.0-1) trusty/esm_php-horde-util: DNE (trusty was not-affected [2.3.0-1]) utopic_php-horde-util: not-affected (2.3.0-1) vivid_php-horde-util: not-affected (2.3.0-1) vivid/stable-phone-overlay_php-horde-util: DNE vivid/ubuntu-core_php-horde-util: DNE wily_php-horde-util: not-affected (2.3.0-1) xenial_php-horde-util: not-affected (2.3.0-1) yakkety_php-horde-util: not-affected (2.3.0-1) zesty_php-horde-util: not-affected (2.3.0-1) devel_php-horde-util: not-affected (2.3.0-1) Patches_horde3: upstream_horde3: needs-triage lucid_horde3: ignored (reached end-of-life) precise_horde3: ignored (reached end-of-life) precise/esm_horde3: DNE (precise was needed) quantal_horde3: ignored (reached end-of-life) saucy_horde3: ignored (reached end-of-life) trusty_horde3: DNE trusty/esm_horde3: DNE utopic_horde3: DNE vivid_horde3: DNE vivid/stable-phone-overlay_horde3: DNE vivid/ubuntu-core_horde3: DNE wily_horde3: DNE xenial_horde3: DNE yakkety_horde3: DNE zesty_horde3: DNE devel_horde3: DNE