Source: php-horde-imp Version: 6.2.27-3.1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for php-horde-imp. CVE-2026-65053[0]: | Horde IMP's AppleDouble MIME viewer writes an attacker-controlled | attachment name into an HTML status block without escaping it. In | lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of | the data part with IMP_Contents::getPartName(), which returns the | MIME part's own name parameter as supplied by the message, and | passes it through sprintf into the text of an IMP_Mime_Status | object. IMP_Mime_Status::__toString() concatenates each text entry | directly into the surrounding table markup, so the value reaches the | rendered page verbatim. A message crafted as multipart/appledouble | whose data part carries markup in its name parameter therefore | executes script in the context of any user who views it, and the | payload persists in the mailbox. Exploitation requires no account on | the target system, only the ability to send mail to a user. Version | 7.2.0 escapes the value with htmlspecialchars(). The researcher | additionally chains this flaw with the arbitrary file read of | CVE-2026-58451, and reports that script running in an | administrator's session can reach an application code-execution | path. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-65053 https://www.cve.org/CVERecord?id=CVE-2026-65053 [1] https://github.com/horde/imp/pull/107 [2] https://github.com/horde/imp/commit/f31449a12e3f945c90015d29524925c4c43f6324 [3] https://blog.evan.lat/posts/CVE-2026-65053/ Please adjust the affected versions in the BTS as needed. Regards, Salvatore

