---
title: "CVE-2008-0807\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-0807?format=md
keywords: index, follow
---

# CVE-2008-0807

Publication date 19 February 2008

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before
2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware
before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not
properly check access rights, which allows remote authenticated users to
modify address data via a modified object\_id parameter to edit.php, as
demonstrated by modifying a personal address book entry when there is write
access to a shared address book.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| turba2 | 9.10 karmic | Fixed 2.1.7-1 |
| 9.04 jaunty | Fixed 2.1.7-1 |
| 8.10 intrepid | Fixed 2.1.7-1 |
| 8.04 LTS hardy | Fixed 2.1.7-1 |
| 7.10 gutsy | Ignored end of life, was needed |
| 7.04 feisty | Ignored end of life, was needed |
| 6.10 edgy | Ignored end of life, was needed |
| 6.06 LTS dapper | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0807)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-0807)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-0807)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-0807)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2008-0807>
