Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-362,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| htmlcleaner_project | htmlcleaner | 1.0 |
| htmlcleaner_project | htmlcleaner | 2.2 |
| htmlcleaner_project | htmlcleaner | 2.4 |
| open-xchange | open-xchange_appsuite | 7.2.2 |
| htmlcleaner_project | htmlcleaner | 1.12 |
| htmlcleaner_project | htmlcleaner | 1.13 |
| htmlcleaner_project | htmlcleaner | 2.2.1 |
| htmlcleaner_project | htmlcleaner | * |
| htmlcleaner_project | htmlcleaner | 0.9 |
| htmlcleaner_project | htmlcleaner | 2.1 |
| htmlcleaner_project | htmlcleaner | 2.0 |
| htmlcleaner_project | htmlcleaner | 0.8 |
| htmlcleaner_project | htmlcleaner | 1.4 |
| htmlcleaner_project | htmlcleaner | 1.2 |
| htmlcleaner_project | htmlcleaner | 1.55 |
| htmlcleaner_project | htmlcleaner | 1.6 |
| htmlcleaner_project | htmlcleaner | 1.3 |
| htmlcleaner_project | htmlcleaner | 1.1 |
| htmlcleaner_project | htmlcleaner | 1.0.5 |
| htmlcleaner_project | htmlcleaner | 1.5 |
An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
Products Affected
| Vendor | Product | Version |
|---|---|---|
| htmlcleaner_project | htmlcleaner | * |