| Summary: | www-apps/coppermine < 1.4.12 Possible Remote SQL Injection (CVE-2007-0122) | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Executioner <keith> | ||||
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> | ||||
| Status: | RESOLVED FIXED | ||||||
| Severity: | minor | CC: | beu, cilly, mail, vivo, web-apps | ||||
| Priority: | Highest | ||||||
| Version: | unspecified | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| URL: | http://www.milw0rm.com/exploits/3085 | ||||||
| Whiteboard: | ~3 [noglsa] | ||||||
| Package list: | Runtime testing required: | --- | |||||
| Attachments: |
|
||||||
|
Description
Executioner
2007-01-06 09:58:39 UTC
Created attachment 105627 [details, diff]
tentative fix (un-checked)
Last time, around two years ago I checked coppermine it was in a strong need for a security review.
The attached patch should fix this particular vulnerability but every query should be checked in the package.
the patch apply to version 1.4.10, so it need a version bump too.
web-apps please advise. Web-apps any news on this one? *** Bug 173966 has been marked as a duplicate of this bug. *** any news here? Security, please feel free to mask. What about contacting upstream? Seems that upstream released 1.4.11: http://secunia.com/advisories/25846/ heya webapss, please bump to 1.4.11 Web-apps do you want to bump or dump(mask) the package? web-apps, any news here? Bumped to 1.4.12. Sorry for the delay. I'll mark it as fixed. |