| Bug#: 218625 (CVE-2008-2041) | Product: Gentoo Security | Version: unspecified | Platform: All |
| OS/Version: Linux | Status: RESOLVED | Severity: major | Priority: P2 |
| Resolution: FIXED | Assigned To: security@gentoo.org | Reported By: smoothp9nguin@gmail.com | |
| Component: Vulnerabilities | |||
| URL: http://secunia.com/advisories/29790/ | |||
| Summary: www-apps/egroupware <1.4.004 File Upload Vulnerability (CVE-2008-2041) | |||
| Keywords: | |||
| Status Whiteboard: C1 [glsa] | |||
| Opened: 2008-04-20 18:55 0000 | |||
| Description: | Opened: 2008-04-20 18:55 0000 |
Secunia: Description: A vulnerability has been reported in eGroupWare, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an error related to FCKEditor. This can be exploited to e.g. upload malicious files and execute arbitrary PHP code, but requires that a directory is writable by the webserver. This may be related to: SA27123http://secunia.com/advisories/29790/ The vulnerability is reported in versions prior to 1.4.004. Solution: Update to version 1.4.004.
Arches, please test and mark stable: =www-apps/egroupware-1.4.004 Target keywords : "alpha amd64 hppa ppc release x86"
might want to include bug 214212 in the GLSA