CVE-2014-1691
Publication date 1 April 2014
Last updated 24 July 2024
Ubuntu priority
Description
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| horde3 | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| php-horde-util | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |