Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Debian: DSA 899-1 Moderate: Egroupware Remote Programming Issues

debian
Calendar Grey November 17, 2005
Debian Logo
Several vulnerabilities in EGroupware have been patched with updated Debian packages; advised to upgrade for enhanced security.
Updated package.

Summary


Maksymilian Arciemowicz discoverd several cross site scripting
problems in phpsysinfo, which are also present in the imported
version in egroupware and of which not all were fixed in DSA 724.

CVE-2005-2600

Alexander Heidenreich discovered a cross-site scripting problem in
the tree view of FUD Forum Bulletin Board Software, which is also
present in egroupwre and allows remote attackers to read private
posts via a modified mid parameter.

CVE-2005-3347

Christopher Kunz discovered that local variables get overwritten
unconditionally in phpsyinfo, which are also present in
egroupware, and are trusted later, which could lead to the
inclusion of arbitrary files.

CVE-2005-3348

Christopher Kunz discovered that user-supplied input is used
unsanitised in phpsyinfo and imported in egroupware, causing a
HTTP Response splitting problem.

The old stable distribution (woody) does not contain egroupware packages.

For the stable distribu...

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here