Bug 209960 (CVE-2008-0807)

Summary: www-apps/horde-turba < 2.1.7 Adress Book Access rights not checked properly (CVE-2008-0807)
Product: Gentoo Security Reporter: Robert Buchholz (RETIRED) <rbu>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Severity: minor    
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [noglsa]
Package list:
Runtime testing required: ---

Description Robert Buchholz (RETIRED) gentoo-dev 2008-02-13 04:55:08 UTC
Tomas Hoger from RedHat:
It was reported that turba does not properly check permissions on address books,
allowing users to modify addresses in other users' address books.  This problem
affects both shared and non-shared address books.  Knowing (or guessing) the
object_id seems to be sufficient to allow modification of other users' addresses.

More information can be found in Debian bug report, which also contains some
proposed patches:

Upstream bug report:
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-02-16 01:51:39 UTC
Turba 2.1.7 is out with the patches, final versions can also be found at Debian's.

Please bump.
Comment 2 SpanKY gentoo-dev 2008-02-17 02:02:43 UTC
horde-turba-2.1.7 is in the tree
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-02-18 04:26:50 UTC
Arches, please test and mark stable:
Target keywords : "alpha amd64 hppa ppc release sparc x86"
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2008-02-19 09:42:21 UTC
Vapier, seems horde-webmail also ships a copy, please bump to 1.0.5.
Comment 6 SpanKY gentoo-dev 2008-02-20 19:48:33 UTC
horde-webmail is updated in the tree now
Comment 7 Christian Faulhammer (RETIRED) gentoo-dev 2008-02-21 07:06:01 UTC
(In reply to comment #6)
> horde-webmail is updated in the tree now

 That is 1.0.5, only ~arch, so no need to mark stable.
Comment 8 Christian Faulhammer (RETIRED) gentoo-dev 2008-02-21 07:48:47 UTC
x86 stable
Comment 9 Raúl Porcel (RETIRED) gentoo-dev 2008-02-21 11:00:08 UTC
alpha/sparc stable
Comment 10 Jeroen Roovers (RETIRED) gentoo-dev 2008-02-21 16:51:58 UTC
Stable for HPPA.
Comment 11 Tobias Scherbaum (RETIRED) gentoo-dev 2008-02-22 13:59:33 UTC
ppc stable
Comment 12 Lars Hartmann 2008-02-24 09:07:11 UTC
can someone please add CVE-2008-0807 to the topic?
Comment 13 Steve Dibb (RETIRED) gentoo-dev 2008-02-25 19:34:51 UTC
amd64 stable
Comment 14 Sune Kloppenborg Jeppesen gentoo-dev 2008-02-25 20:16:37 UTC
This one is ready for GLSA vote.
Comment 15 Peter Volkov (RETIRED) gentoo-dev 2008-02-25 20:49:32 UTC
Fixed in release snapshot
Comment 16 Sune Kloppenborg Jeppesen gentoo-dev 2008-02-26 20:38:26 UTC
I tend to vote NO.
Comment 17 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-02-26 21:12:02 UTC
voting NO too, and closing.