Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.
{ "binaries": [ { "binary_name": "php-horde-turba", "binary_version": "4.2.12-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "php-horde-turba", "binary_version": "4.2.21-1ubuntu1" } ] }