Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 278816

Summary: <www-apps/joomla-1.5.13: Multiple vulnerabilities
Product: Gentoo Security Reporter: Christian Faulhammer (RETIRED) <fauli>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: web-apps
Priority: High    
Version: unspecified   
Hardware: All   
OS: All   
Whiteboard: ~4 [noglsa]
Package list:
Runtime testing required: ---

Description Christian Faulhammer (RETIRED) gentoo-dev 2009-07-23 09:33:46 UTC
Description

Tiny browser included with TinyMCE 3.0 editor allowed files to be uploaded and removed without logging in.
Affected Installs

Version 1.5.12 only
Solution

Upgrade to latest Joomla! version (1.5.13 or newer).

Reported by Patrice Lazareff.


Description
Some files were missing the check for JEXEC.  These scripts will then expose internal path information of the host.
Affected Installs
All 1.5.x installs prior to and including 1.5.12 are affected.
Solution
Upgrade to latest Joomla! version (1.5.13 or newer).
Reported by Juan Galiana Lara (Internet Security Auditors)
Comment 1 Christian Faulhammer (RETIRED) gentoo-dev 2009-07-23 09:41:08 UTC
ebuild in the tree, package hard masked
Comment 2 Tobias Heinlein (RETIRED) gentoo-dev 2009-07-31 15:57:02 UTC
Thanks, Christian.