PDA

View Full Version : Horde arbitrary file inclusion vulnerability



Jamie G
March 7th, 2008, 12:01
Received this today in my mail box :)

An arbitrary file inclusion vulnerability has been discovered in the
Horde
webmail application. At present, we can confirm that this security
vulnerability in question affects Horde 3.1.6 and earlier. Based on
incomplete information at this time, we also believe this affects Horde
Groupware 1.0.4 and earlier as well (cPanel does not use Horde
Groupware
at this time).

cPanel customers should update their cPanel and WHM servers immediately
to
prevent any chance of compromise. The patch will be available in builds
11.18.2 and greater (or 11.19.2 and greater for EDGE systems). The
updated
builds will be available immediately to all fast update servers. The
builds will be available to all other update servers within one hour of
this posting.


To check which version of cPanel and WHM is on your server, simply log
into WebHost Manager (WHM) and look in the top right corner, or execute
the following command from the command line as root:

/usr/local/cpanel/cpanel -V

You can upgrade your server by navigating to 'cPanel' -> 'Upgrade to
Latest Version' in WebHost Manager or by executing the following from
the
command line as root:

/scripts/upcp


It is recommended that all use of Horde 3.1.6 and earlier be stopped
(on
cPanel and non-cPanel systems alike) until Horde updates can be
applied.
You can disable Horde on your cPanel system by unchecking the box next
to
'Server Configuration' -> 'Tweak Settings' -> 'Mail' -> 'Horde Webmail'
within WHM, and saving the page with the new settings.


We would like to thank HostGator for providing the initial details in
their report of this vulnerability.

Decker
March 7th, 2008, 12:49
Who was it from - the header of the mail?

Host Factory
March 7th, 2008, 18:05
from cpanel, i got one as well

Eclouds
March 7th, 2008, 18:37
We sent that out to our clients yesterday.

MWH-Jon
March 7th, 2008, 22:45
cPanel sent a message out not too long ago

Decker
March 8th, 2008, 01:12
Never got that and I'm on the cPanel mailer, check the actual header again, don't like Horde/Golem/Imp as it's crap anyway :)

Cam.
March 8th, 2008, 04:34
It's from cPanel, I got it too ;)

Here's the header:

Delivered-To: MYEMAIL
Received: by 10.110.32.5 with SMTP id f5cs633516tif;
Fri, 7 Mar 2008 02:38:11 -0800 (PST)
Received: by 10.70.72.11 with SMTP id u11mr1231256wxa.39.1204886278521;
Fri, 07 Mar 2008 02:37:58 -0800 (PST)
Return-Path: <news-bounces@cpanel.net>
Received: from mx1.cpanel.net (mx1.cpanel.net [208.74.121.68])
by mx.google.com with ESMTP id i6si7412028wxd.21.2008.03.07.02.37.22;
Fri, 07 Mar 2008 02:37:58 -0800 (PST)
Received-SPF: pass (google.com: domain of news-bounces@cpanel.net designates 208.74.121.68 as permitted sender) client-ip=208.74.121.68;
DomainKey-Status: good (test mode)
Authentication-Results: mx.google.com; spf=pass (google.com: domain of news-bounces@cpanel.net designates 208.74.121.68 as permitted sender) smtp.mail=news-bounces@cpanel.net; domainkeys=pass (test mode) header.From=news-bounces@cpanel.net
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=cpanel.net;
h=Received:Received:Message-ID:Date:From:User-Agent:MIME-Version:To:Subject:X-BeenThere:X-Mailman-Version:Precedence:List-Id:List-Unsubscribe:List-Archive:List-Post:List-Help:List-Subscribe:Content-Type:Content-Transfer-Encoding:Sender:Errors-To:X-AntiAbuse:X-AntiAbuse:X-AntiAbuse:X-AntiAbuse:X-AntiAbuse;
b=TpAJpant14qyjSQvqmlpkdKW/iEFWTcrBoIWYkju7fCkg4c67mqwDz2OSG0tne/h0heJVwO57VmJiZK4Dk7K+VyFNvu4yqKAGH8WQFQrjBeURBW+1kI0AxPdDfE 3Jmwo;
Received: from localhost.cpanel.net ([127.0.0.1] helo=mx1.cpanel.net)
by mx1.cpanel.net with esmtp (Exim 4.68)
(envelope-from <news-bounces@cpanel.net>)
id 1JXQKg-0002a5-Cu; Thu, 06 Mar 2008 18:21:06 -0600
Received: from 70.15.84.15.res-cmts.blo.ptd.net ([70.15.84.15]
helo=[192.168.1.8]) by mx1.cpanel.net with esmtpa (Exim 4.68)
(envelope-from <eric@cpanel.net>) id 1JXQKS-0002Zf-AB
for news@cpanel.net; Thu, 06 Mar 2008 18:20:52 -0600
Message-ID: <47D08A67.10703@cpanel.net>
Date: Thu, 06 Mar 2008 19:20:55 -0500
From: Eric Gregory <eric@cpanel.net>
User-Agent: Thunderbird 2.0.0.12 (Windows/20080213)
MIME-Version: 1.0
To: news@cpanel.net
Subject: [cPanel-News] ***URGENT*** cPanel News Update ***URGENT***
X-BeenThere: news@cpanel.net
X-Mailman-Version: 2.1.9.cp2
Precedence: list
List-Id: cPanel News <news_cpanel.net.cpanel.net>
List-Unsubscribe: <http://mail.cpanel.net/mailman/listinfo/news_cpanel.net>,
<mailto:news-request@cpanel.net?subject=unsubscribe>
List-Archive: <http://mail.cpanel.net/mailman/private/news_cpanel.net>
List-Post: <mailto:news@cpanel.net>
List-Help: <mailto:news-request@cpanel.net?subject=help>
List-Subscribe: <http://mail.cpanel.net/mailman/listinfo/news_cpanel.net>,
<mailto:news-request@cpanel.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: news-bounces@cpanel.net
Errors-To: news-bounces@cpanel.net
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - mx1.cpanel.net
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - cpanel.net

You'll get it eventually Decker ;)

Decker
March 8th, 2008, 05:50
Looks gen enough!

Then again as I said I hate the Horde suite :D clunky crap that it is.

Jamie G
March 8th, 2008, 06:14
Yeah i agree with you Decker, I just dont like the layout of it.

Decker
March 8th, 2008, 06:22
Not just the layout - it just sucks and blows at the same time.

It's 20 years back when it would have been cool - it's also a hog and a sod to install and config to get working 'properly' it's had its day time to retire it, squirrel isn't much better in todays market, but I like the tag line :D

Patrick
March 8th, 2008, 13:44
Roundecube ftw! :)