[NEWS] eGroupWare Unsent Attachement Disclosure
SecuriTeam <[email protected]>
| Newsgroups | gmane.comp.security.securiteam |
|---|---|
| Message-ID | <[email protected]> |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - eGroupWare Unsent Attachement Disclosure ------------------------------------------------------------------------ SUMMARY <http://www.egroupware.org/> eGroupware is "a very popular open source web based collaboration software that can be used within an intranet, or externally via the Internet to build a community and/or help coordinate large projects". The eGroupWare open-source software has a flaw that can cause the exposure of sensitive files due to a programmatic error in the handling of unsent emails. DETAILS Vulnerable Systems: * eGroupWare version 1.001 * eGroupWare version 1.006 If a user composes a message and attaches a file and then decides not to send the message, the attachment will get sent to the next person the user emails. There is no indication in the message window that the file from the previous message is still attached (unless the user clicks on the button to attach a file to the second message). Walk through: Login to eGroupWare using an account that has email configured. Step 1. After logging in, select the email icon on the tool bar. Step 2. Click the Compose button to create a new message and attach a file. Do NOT click Send. Step 3. Without sending the message, return to the inbox. You can click the inbox link on the left of the email icon on the toolbar. Step 4. You are now back at the main inbox screen. Click on the Compose link again. Step 5. Enter an email address (a personal account or one of a trusted friend, preferably), a subject and brief message if you like and click Send. Step 6. Now check the email for the account you sent the message to above. The attachment from the canceled message in step 2 will be attached. ADDITIONAL INFORMATION The information has been provided by <mailto:[email protected]> Gerald Quakenbush. The original article can be found at: <http://www.mastermindsecuritygroup.com> http://www.mastermindsecuritygroup.com ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] In order to subscribe to the mailing list, simply forward this email to: [email protected] ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.