|
Gentoo: horde Remote session hijacking |
|
|
|
Posted by LinuxSecurity.com Team
|
An attacker could send an email to the victim who ago use of HORDE MTAin order to push it to visit a website. The website in issue log all theaccesses and describe in the particular the origin of every victim.
- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200309-02.1
- - ---------------------------------------------------------------------
� � � � � PACKAGE : horde
� � � � � SUMMARY : session hijacking
� � � � � � �DATE : 2003-09-01 14:38 UTC
� � � � � EXPLOIT : remote
VERSIONS AFFECTED : =horde-2.2.4_rc2
� � � � � � � CVE :
- - ---------------------------------------------------------------------
This advisory contains the correct values for VERSIONS AFFECTED and
FIXED VERSION
SOLUTION
It is recommended that all Gentoo Linux users who are running
net-www/horde upgrade to horde-2.2.4_rc2 as follows:
emerge sync
emerge horde
emerge clean
- - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz
- - ---------------------------------------------------------------------
|