Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.
                
            References
                    | Link | Resource | 
|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2013-08/0115.html | Exploit | 
| http://sourceforge.net/p/htmlcleaner/bugs/86/ | Exploit | 
Configurations
                    Configuration 1 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2013-09-05 04:44
Updated : 2013-10-08 10:33
NVD link : CVE-2013-5035
Mitre link : CVE-2013-5035
JSON object : View
CWE
                
                    
                        
                        CWE-362
                        
            Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
                htmlcleaner_project
- htmlcleaner
 
open-xchange
- open-xchange_appsuite
 


