CVE-2013-5035

Published Sep 5, 2013

Last updated 11 years ago

Overview

Description
Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.
Source
cve@mitre.org
NVD status
Analyzed

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
4.9
Impact score
4.9
Exploitability score
6.8
Vector string
AV:N/AC:M/Au:S/C:P/I:P/A:N

Weaknesses

nvd@nist.gov
CWE-362

Evaluator

Comment
-
Impact
CVSS score reflects vendor comments provided in http://archives.neohapsis.com/archives/bugtraq/2013-08/0115.html
Solution
CVSS score reflects vendor comments provided in http://archives.neohapsis.com/archives/bugtraq/2013-08/0115.html

Configurations