ubuntu · CVE-2017-7413

Quick triage

Priority: medium Published: 2017-04-04 14:59:00 UTC Updated: 2025-08-26 12:01:19 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-7413 medium priority: Ubuntu including 1 source packages (php-horde-crypt), 21 status rows across 21 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, mantic, noble, oracular, plucky, precise, questing, trusty, upstream, xenial, yakkety, zesty): DNE 12, not-affected 4, ignored 3, needed 1, released 1.

Description:

In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has PGP features enabled in their preferences, and attempts to encrypt an email addressed to a maliciously crafted email address.

cvelogic Threat Intelligence