Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 26786 - dev-php/phpgroupware
Summary: dev-php/phpgroupware
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Highest critical (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-08-17 01:20 UTC by Daniel Ahlberg (RETIRED)
Modified: 2003-09-22 01:36 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Ahlberg (RETIRED) gentoo-dev 2003-08-17 01:20:57 UTC
________________________________________________________________________ 
 
                Mandrake Linux Security Update Advisory 
________________________________________________________________________ 
 
Package name:           phpgroupware 
Advisory ID:            MDKSA-2003:077 
Date:                   July 23rd, 2003 
 
Affected versions:      8.2, 9.0, 9.1, Corporate Server 2.1 
________________________________________________________________________ 
 
Problem Description: 
 
 Several vulnerabilities were discovered in all versions of phpgroupware 
 prior to 0.9.14.006.  This latest version fixes an exploitable 
 condition in all versions that can be exploited remotely without 
 authentication and can lead to arbitrary code execution on the web 
 server.  This vulnerability is being actively exploited. 
 
 Version 0.9.14.005 fixed several other vulnerabilities including 
 cross-site scripting issues that can be exploited to obtain 
 sensitive information such as authentication cookies. 
 
 This update provides the latest stable version of phpgroupware and all 
 users are encouraged to update immediately.  In addition, you should 
 also secure your installation by including the following in your Apache 
 configuration files: 
 
   <Directory /var/www/html/phpgroupware> 
     <Files ~ "\.inc\.php$"> 
       Order allow,deny 
       Deny from all 
     </Files> 
   </Directory> 
________________________________________________________________________ 
 
References: 
 
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0577 
  http://www.security-corporation.com/articles-20030702-005.html 
________________________________________________________________________
Comment 1 Martin Holzer (RETIRED) gentoo-dev 2003-09-10 15:26:25 UTC
phpgroupware-0.9.14.006.ebuild
is already in cvs and marked stable
Comment 2 solar (RETIRED) gentoo-dev 2003-09-22 01:36:35 UTC
Thanks Martin 
changing resolution to FIXED