Horde Application Framework contains a flaw that may allow a malicious user to overwrite local files. The issue is triggered when an unspecified error occurs. It is possible that the flaw may allow arbitrary overwrites of local files resulting in a loss of integrity.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 3.2.5, 3.3.5 or higher, as it has been reported to fix this vulnerability. In addition, the vendor has released a patch for some older versions.