Gentoo: GLSA-200611-22: Ingo H3: Folder name shell command injection
Summary
Gentoo Linux Security Advisory GLSA 200611-22
https://security.gentoo.org/
Severity: Normal
Title: Ingo H3: Folder name shell command injection
Date: November 27, 2006
Bugs: #153927
ID: 200611-22
Synopsis
=======
Ingo H3 is vulnerable to arbitrary shell command execution when
handling procmail rules.
Background
=========
Ingo H3 is a generic frontend for editing Sieve, procmail, maildrop and
IMAP filter rules.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-apps/horde-ingo < 1.1.2 >= 1.1.2
==========
Ingo H3 fails to properly escape shell metacharacters in procmail
rules.
Impact
=====
A remote authenticated attacker could craft a malicious rule w...
Resolution
References
Availability
Concerns
Background