Home | Docs | Forums | Lists | Bugs | Planet | Store | GMN | Get Gentoo!
Not eligible to see or edit group visibility for this bug.
View Bug Activity | Format For Printing | XML | Clone This Bug
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.
Created an attachment (id=147233) [details] patch
maintainers - please provide an updated ebuild
1.4.4-r1 in cvs
Arches, please test and mark stable www-apps/roundup-1.4.4-r1 target : "amd64 ppc release sparc x86"
x86 stable
amd64 stable
Sparc stable.
ppc stable
Removed vulnerable version. webapps done.
Time for GLSA decision. I vote YES.
Fixed in release snapshot.
Voting YES and filing request.
GLSA 200805-21