| Summary: | www-apps/online-bookmarks <0.6.28 Login bypass, XSS, SQL injection (CVE-2004-2155,CVE-2006-{6358,6359}) | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Robert Buchholz (RETIRED) <rbu> |
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED FIXED | ||
| Severity: | minor | ||
| Priority: | High | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | B3 [glsa] | ||
| Package list: | Runtime testing required: | --- | |
|
Description
Robert Buchholz (RETIRED)
2008-08-17 23:27:32 UTC
Maybe we can bump to the latest version here, haven't looked at the code yet. Updated to online-bookmarks-0.6.28. The change log suggests that all sec issues have been fixed in that version. Targets: ppc Thanks for investigating. ppc stable time for GLSA decision, I vote YES. Removed vulnerable version. webapps done. YES too, request filed. GLSA 200901-08, sorry for the delay. |