Summary
The remote host is missing an update to horde3
announced via advisory DSA 884-1.
Mike O'Connor discovered that the default installation of Horde3 on Debian includes an administrator account without a password. Already configured installations will not be altered by this update.
The old stable distribution (woody) does not contain horde3 packages.
Solution
For the stable distribution (sarge) this problem has been fixed in version 3.0.4-4sarge1.
For the unstable distribution (sid) this problem has been fixed in version 3.0.5-2
We recommend that you verify your horde3 admin account if you have installed Horde3.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20884-1
Severity
Classification
-
CVE CVE-2005-3344 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities