Source: php-horde-imp
Version: 6.2.27-3.1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for php-horde-imp.

CVE-2026-65053[0]:
| Horde IMP's AppleDouble MIME viewer writes an attacker-controlled
| attachment name into an HTML status block without escaping it. In
| lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of
| the data part with IMP_Contents::getPartName(), which returns the
| MIME part's own name parameter as supplied by the message, and
| passes it through sprintf into the text of an IMP_Mime_Status
| object. IMP_Mime_Status::__toString() concatenates each text entry
| directly into the surrounding table markup, so the value reaches the
| rendered page verbatim. A message crafted as multipart/appledouble
| whose data part carries markup in its name parameter therefore
| executes script in the context of any user who views it, and the
| payload persists in the mailbox. Exploitation requires no account on
| the target system, only the ability to send mail to a user. Version
| 7.2.0 escapes the value with htmlspecialchars(). The researcher
| additionally chains this flaw with the arbitrary file read of
| CVE-2026-58451, and reports that script running in an
| administrator's session can reach an application code-execution
| path.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-65053
    https://www.cve.org/CVERecord?id=CVE-2026-65053
[1] https://github.com/horde/imp/pull/107
[2] https://github.com/horde/imp/commit/f31449a12e3f945c90015d29524925c4c43f6324
[3] https://blog.evan.lat/posts/CVE-2026-65053/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to