Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 97460 - www-apps/phpgroupware: XML-RPC vulnerability (CAN-2005-1921)
Summary: www-apps/phpgroupware: XML-RPC vulnerability (CAN-2005-1921)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Other
: High major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B1 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-06-30 01:52 UTC by Thierry Carrez (RETIRED)
Modified: 2005-07-10 12:35 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2005-06-30 01:52:53 UTC
phpgroupware includes an affected XMLRPC PHP library and should be patched.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-06-30 02:06:07 UTC
Ccing stuart. Feel free to open this bug as soon as you think it's public enough.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-07-01 10:13:32 UTC
I just sent an email to upstream to make sure they are aware of the issue.
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-07-01 13:32:50 UTC
Public from Gulftech advisory
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-07-02 02:25:56 UTC
Upstream is aware and working on it.
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2005-07-05 00:41:26 UTC
Upstream released fixed version 0.9.16.006
Comment 6 Aaron Walker (RETIRED) gentoo-dev 2005-07-06 03:21:00 UTC
In CVS.  amd64 and ppc please stable.
Comment 7 Aaron Walker (RETIRED) gentoo-dev 2005-07-06 03:23:00 UTC
Also, could whoever is the last arch to do it, please remove the two previous
versions (0.9.16.00[45])?
Comment 8 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-07-06 13:03:27 UTC
ppc done, blubb started with amd64
Comment 9 Simon Stelling (RETIRED) gentoo-dev 2005-07-06 13:21:27 UTC
amd64 stable; didn't remove old ebuilds yet since x86 is still testing
Comment 10 Simon Stelling (RETIRED) gentoo-dev 2005-07-06 13:27:15 UTC
old versions removed:

ka0ttic blubb: um there was never x86 stablew
ka0ttic certainly not going to mark it stable now
blubb i see
blubb ka0ttic: i'll remove the old versions then
ka0ttic blubb: thanks
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2005-07-06 13:40:06 UTC
Should be ready for GLSA
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-06 14:12:31 UTC
Waiting for egroupware to be ready for GLSA. 
Comment 13 Stefan Cornelius (RETIRED) gentoo-dev 2005-07-10 12:07:16 UTC
egroupware finally ready for GLSA -> this one is ready, too.
Comment 14 Matthias Geerdsen (RETIRED) gentoo-dev 2005-07-10 12:35:23 UTC
GLSA 200507-08

thanks everyone