Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Sign up!
EnGarde Community
What is the most important Linux security technology?
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Latest Newsletters
Linux Security Week: March 23rd, 2015
Linux Advisory Watch: March 20th, 2015
LinuxSecurity Newsletters
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

Debian: New phpgroupware packages fix several vulnerabilities Print E-mail
User Rating:      How can I rate this item?
Posted by Benjamin D. Thomas   
Debian Updated package.
- --------------------------------------------------------------------------
Debian Security Advisory DSA 898-1                                        Martin Schulze
November 17th, 2005           
- --------------------------------------------------------------------------

Package        : phpgroupware
Vulnerability  : programming errors
Problem-Type   : remote
Debian-specific: no
CVE ID         : CVE-2005-0870 CVE-2005-3347 CVE-2005-3348
Debian Bug     : 301118

Several vulnerabilities have been discovered in phpsysinfo, a PHP
based host information application.  The Common Vulnerabilities and
Exposures project identifies the following problems: 


    Maksymilian Arciemowicz discoverd several cross site scripting
    problems, of which not all were fixed in DSA 724.


    Christopher Kunz discovered that local variables get overwritten
    unconditionally and are trusted later, which could lead to the
    inclusion of arbitrary files.


    Christopher Kunz discovered that user-supplied input is used
    unsanitised, causing a HTTP Response splitting problem.

For the old stable distribution (woody) these problems have been fixed in
version 0.9.14-0.RC3.2.woody5.

For the stable distribution (sarge) these problems have been fixed in

For the unstable distribution (sid) these problems have been fixed in

We recommend that you upgrade your phpgroupware packages.

Upgrade Instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.0 alias woody
- --------------------------------

  Source archives:
      Size/MD5 checksum:     1648 b566e2f51056fa8ac7d8b251d7a96ff9
      Size/MD5 checksum:   450241 6eeab6967838532bd4ff397e3594de18
      Size/MD5 checksum:  8356188 22e715d0884d09aa848d694701a85b6b

  Architecture independent components:
      Size/MD5 checksum:    79298 c2b985d562329e5dadaa007053b13b0d
      Size/MD5 checksum:   142622 c5773f488d74e817e3dd017f7d63f396
      Size/MD5 checksum:   283750 026bc3f52bdf4cfb9e89396b1d658f05
      Size/MD5 checksum:  2110096 d07c843fe0dc2f56c908ab62a7c3932f
      Size/MD5 checksum:    40660 95ba9a9bc2a615a0f4fbec5de1af138d
      Size/MD5 checksum:   121642 aa2250a0f423b29960a859ceca8f536a
      Size/MD5 checksum:    63996 a5adeb85c78d0b0d934a4c3d89533120
      Size/MD5 checksum:   224328 8ff4ae362e2943bf5723f3b452e38874
      Size/MD5 checksum:    19520 a0ad48a10a9ef92b21385dac1647951c
      Size/MD5 checksum:    60344 5c914d9839df514a7797b66e03abcb34
      Size/MD5 checksum:   326802 f6dbeb5cfd3f1e8fcd30577d74e0c3a3
      Size/MD5 checksum:    89716 46184743bb37272b7575fefe07769e5f
      Size/MD5 checksum:    19506 9bee51413e1d2e7e233d72320d974648
      Size/MD5 checksum:    41384 c7b071fd0896d64c90c85f034ead73ec
      Size/MD5 checksum:    45948 5d7b9021bbe8645e376b652e321a2864
      Size/MD5 checksum:    47580 274aa69642d97f7eae830e5a2f8853a5
      Size/MD5 checksum:   313796 a8fcc446290f7ca6d8770a5cf6d133b5
      Size/MD5 checksum:    37968 a339be1b0b48c3f25d0c13685ec32c94
      Size/MD5 checksum:    48320 d580900a62cfc91c6ed00c28dac23de3
      Size/MD5 checksum:    39984 8c59ea1ecf380674e2af66120b3fcb72
      Size/MD5 checksum:    59948 76b9143103e8f3496dd9ad58790039f8
      Size/MD5 checksum:    24306 ba9f2259950afb73c3617e52945f933f
      Size/MD5 checksum:    39250 72811641f7f714455dc8216ae3ad470f
      Size/MD5 checksum:    93448 44146630a16580e20eb511ddb710d9ac
      Size/MD5 checksum:    89894 e3c507eeffe88fb1e0dfccb3678a81f7
      Size/MD5 checksum:    93100 f87c371b8b37455f5d3766d65e081cbe
      Size/MD5 checksum:    30260 9294cbfad065ca30240a25cca10ab1c5
      Size/MD5 checksum:    26678 07d0ae30f508575cd66b820b7be8d617
      Size/MD5 checksum:    32100 77281a49f092426a3d68d55d0df67256
      Size/MD5 checksum:    45032 7ff68e4368db0ae58a26dccc6095f762
      Size/MD5 checksum:    27724 415876cf611fb4d676785923b3dd4d7b
      Size/MD5 checksum:    22260 71f59501cb31e2ac155dda3533f8d8a0
      Size/MD5 checksum:    35596 0432bcee4145c34c13b83c1a097b04cc
      Size/MD5 checksum:    62238 12c217f1885578d005eeb778ae874048
      Size/MD5 checksum:    30190 41f6d69d69ebd5d1cf13c61cc8795790
      Size/MD5 checksum:    46148 de949dd6cd41c6817c40af466d5b2ea2
      Size/MD5 checksum:    86830 d3228f43e0c7e93cb249e7aa06707985
      Size/MD5 checksum:    36458 a81bab670414b8f322b0700694deca6e
      Size/MD5 checksum:   273064 fb1749a7609c2d858388f01c421e4950
      Size/MD5 checksum:    31440 a88512cf06f4bac46cf0ad8a6f2ed046
      Size/MD5 checksum:    23096 d7b9db3f1fe52ccb69a91db466ada9da
      Size/MD5 checksum:    27168 30abd675055b16e1867fc47b7f9f0f03
      Size/MD5 checksum:    43666 f395710610352fa8bb0992473e03e84e
      Size/MD5 checksum:    46672 39d14cff54c5dc978d87d77705f6fa64
      Size/MD5 checksum:    28112 76da6ba398ed66d7819e2bb54a1a5dc5
      Size/MD5 checksum:   498832 92956b14cbe894dce47ca3a792399258
      Size/MD5 checksum:    74958 dd01b3381e6de01f5f484bd3a4e116fe
      Size/MD5 checksum:    26246 d5e2072c9d0ee92112b45aadf393b002

Debian GNU/Linux 3.1 alias sarge
- --------------------------------

  Source archives:
      Size/MD5 checksum:     1613 a7a22d0059c9e0fbe9dc6a180dda1861
      Size/MD5 checksum:    36821 24b9ee58c7351e5ad759004f3de64850
      Size/MD5 checksum: 19442629 5edd5518e8f77174c12844f9cfad6ac4

  Architecture independent components:
      Size/MD5 checksum:   176708 22ff5daa5c3da9c4359458958c4a8210
      Size/MD5 checksum:   186486 61ff479a17df309769400555758b4be4
      Size/MD5 checksum:   101110 0f5158dbadf4074335dae1dac8d9322c
      Size/MD5 checksum:   324210 0b831eb86b630d98548a32ef86e9742e
      Size/MD5 checksum:    23338 b5cbabc134dc0bdd7584d05e8cf1ca93
      Size/MD5 checksum:   434332 9255e255e3737fe45f7358301a8354f5
      Size/MD5 checksum:     6630 80771055932dada464c017bd8ec937ef
      Size/MD5 checksum:    33450 19b7940ea349f48bcc76db69a4177888
      Size/MD5 checksum:    42902 5f25541a98e5837d5ed0f580449436e3
      Size/MD5 checksum:    50592 a810c608dca20a544adce8957294ad6e
      Size/MD5 checksum:  1118084 13f46335c0dbbb4909d31862a3a92aac
      Size/MD5 checksum:  1329600 fe31f9dd77a2c463eb71aff88f5984e6
      Size/MD5 checksum:   180306 516269d09dbfa8a503cf8899179815f9
      Size/MD5 checksum:    91738 8079e7b3f16ac9d269da155a77176d8b
      Size/MD5 checksum:   166508 4fe6e827ca8a0a64147d893ef43ae17d
      Size/MD5 checksum:    45692 52ec682c7169801d202dc0afcc7b9f1f
      Size/MD5 checksum:    36540 2ab8e0f4bc0cc176153cec4b0ef8bbb8
      Size/MD5 checksum:  1355886 87aca5504ca5aeac4219e7731371a510
      Size/MD5 checksum:    64042 df3b3d21b61791d4cf3e1eee415c25dc
      Size/MD5 checksum:    18964 3b4387bf2556061ecdb1456ae3925ac8
      Size/MD5 checksum:     8716 c539c846f5547756b8aa53f6cba1c4a3
      Size/MD5 checksum:   136528 2a2557b6feabe846ddff1a301d7875de
      Size/MD5 checksum:    90760 674ab476f67efe8badd90ece9a8a0f61
      Size/MD5 checksum:    26118 aa5d5a23f20c79c14bc9a6849370ff14
      Size/MD5 checksum:    41436 003c97150c1da9f3812521f2277ec433
      Size/MD5 checksum:    47062 505cbe3eaabc0838e33445ba313ab0f5
      Size/MD5 checksum:    35086 c5e785e89763701bb63782b061c2089b
      Size/MD5 checksum:    20822 88ef1cba9d2f8d3814d95e4b18c7c3ea
      Size/MD5 checksum:    40298 04c2444dd4ebc34a70541eaad89e477c
      Size/MD5 checksum:  9678082 4176bb65f06984af183ea98f38ddb628
      Size/MD5 checksum:   116710 b500b5681e3ad9c7fb9e58ee6355815b
      Size/MD5 checksum:    31650 a69d663710889a65c5e00445da2bb15f
      Size/MD5 checksum:    59750 74e816593527a8db61e6ade7696fe6d7
      Size/MD5 checksum:   120450 e812184d80be8ce7e4a5d52582ef268b
      Size/MD5 checksum:    23616 2d0a6db5dc08631a4149366294c25036
      Size/MD5 checksum:    30070 f4220aec25d9dc4f857c93e29d9b8585
      Size/MD5 checksum:   267402 2cd8c3e2bd2ebcdb1f47cb7fb69419f7
      Size/MD5 checksum:   902722 906af3e7dc66fe42d796e4317c238781
      Size/MD5 checksum:    19312 41653329553a614b6d073583f28df0c4
      Size/MD5 checksum:    24152 a900899343d5a0f95490eda6c6798cce
      Size/MD5 checksum:    22094 711877afe59a6dd5c3cf500ff40f0285
      Size/MD5 checksum:    50388 979958e0910ab1428b88d6146be42d7f
      Size/MD5 checksum:    55902 3932ef425f1f9959a8943d2e6457f54c
      Size/MD5 checksum:    70444 544f88a951610a6b673371f0963cba21
      Size/MD5 checksum:    63086 7c95449de2e66de06b3f4c763e9de168
      Size/MD5 checksum:   156300 4eb60f3560ba1a52265edab63c6f8f2b

  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb stable/updates main
For dpkg-ftp: dists/stable/updates/main
Mailing list:
< Prev   Next >


Latest Features
Peter Smith Releases Linux Network Security Online
Securing a Linux Web Server
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Yesterday's Edition
Tech Companies, Privacy Advocates Call for NSA Reform
Google warns of unauthorized TLS certificates trusted by almost all OSes
How Kevin Mitnick hacked the audience at CeBIT 2015
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2015 Guardian Digital, Inc. All rights reserved.