-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2015.2756
                         php-horde security update
                              4 November 2015

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           php-horde
Publisher:         Debian
Operating System:  Debian GNU/Linux 7
                   Debian GNU/Linux 8
                   UNIX variants (UNIX, Linux, OSX)
                   Windows
Impact/Access:     Cross-site Request Forgery -- Remote with User Interaction
Resolution:        Patch/Upgrade

Original Bulletin: 
   http://www.debian.org/security/2015/dsa-3391

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Debian. It is recommended that administrators 
         running php-horde check for an updated version of the software for 
         their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-3391-1                   security@debian.org
https://www.debian.org/security/                           Florian Weimer
November 03, 2015                     https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : php-horde
Debian Bug     : 803641

It was discovered that the web-based administration interface in the
Horde Application Framework did not guard against Cross-Site Request
Forgery (CSRF) attacks.  As a result, other, malicious web pages could
cause Horde applications to perform actions as the Horde user.

The oldstable distribution (wheezy) did not contain php-horde
packages.

For the stable distribution (jessie), this problem has been fixed in
version 5.2.1+debian0-2+deb8u2.

For the testing distribution (stretch) and the unstable distribution
(sid), this problem has been fixed in version 5.2.8+debian0-1.

We recommend that you upgrade your php-horde packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBAgAGBQJWOStoAAoJEL97/wQC1SS+MHEIAJ2sxGyD96tbSiN0TkkYy6VZ
SmjY9xuw7VE1fDJippuyI3uSWpcg7X1Lp4lZaoa5kNYpbEwTQBAqAlsW7G5sanqt
LguF01ds1w1is4Tw796ukdT12nGY/DFo/t3DwbS+F0DIpZkvR2cNCHIVvw4Uu1mh
Mtr9mQe0oyPshxJoZmsjPSJW3JAlM9PE47YfvgNhONVFFl+95MMcjCzg2boRhl4k
fSS5S2mcZ/C8fRxUHdcywmZ/wE7NReIqBZPRptMWew2oWAENDrtCCGiqIxzoCwnT
s75dtELRXfneQ70bkTZnIyLQZKVDN+1YO9nGaOgCdoyxoT8r+hBuuXnmAtEP3H8=
=PQ4n
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBVjlZ336ZAP0PgtI9AQK7ow/9GWclxEq6c7XCrxZPa2Y0OKiw+zz/mw5S
ALObFN6pEVNOVTTtRSgvj/u8VeeeNeZxfwtNGXxUKxB9YwkOHB5vWIiYVVbozH2R
bBBLRkMABa1wWqPxy3bRNZxXo8eGFzUsHLbdFcbP2bhQDvh41P8q3U4x99JqyS5e
s7/FAedz4WFnwaykNFPbr5hV/L2YcfMWXcQVfo9HhdK3P9X7LF6ouoeVHf7K923o
qkd14TiKtpBZqzzK9r960PVV1uyKQh0KNpmn99z1gRrg3MJ13NNA4Fq1Z8W6ELr1
rUMip0ia3coa/M24JPYttLFxwhlushebYhW2LQCW9cE/XkGDpGC3iPb6NCsdCn13
Jvau8FtW9mCrk2RKsCLODagOnAI86wO9k7XYIZn0jk9E98n0yNQWpvAY/O07ytV5
FB+TUO9ryczXUxlF9o14z/6N48KsxS3hhM6f7MvU0OKrvJcs9ai9Bb1IGzY1TnX9
aAW923AeiH4LIF0e7gTDu0nUgSpYGWiA0Fl9YbFlf0AORVjkiQ+hhgYxjqUMpUDc
gPeJ3nV9/+51Cl/pA+3Fi/noJMj1cQ1eQCfHr2Z6A3sudesFKCR03nhyQ2Sd+iuz
PP3PvkM4JfqOJyFs/Q1fmTZC5TJXzR0fvEWtkCm+la04eBwfIXIv+kQC2ti3qUZs
5L6LfTaB9eE=
=9qdw
-----END PGP SIGNATURE-----