Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 97460

Summary: www-apps/phpgroupware: XML-RPC vulnerability (CAN-2005-1921)
Product: Gentoo Security Reporter: Thierry Carrez (RETIRED) <koon>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: major CC: web-apps
Priority: High    
Version: unspecified   
Hardware: All   
OS: Other   
Whiteboard: B1 [glsa]
Package list:
Runtime testing required: ---

Description Thierry Carrez (RETIRED) gentoo-dev 2005-06-30 01:52:53 UTC
phpgroupware includes an affected XMLRPC PHP library and should be patched.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-06-30 02:06:07 UTC
Ccing stuart. Feel free to open this bug as soon as you think it's public enough.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-07-01 10:13:32 UTC
I just sent an email to upstream to make sure they are aware of the issue.
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-07-01 13:32:50 UTC
Public from Gulftech advisory
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-07-02 02:25:56 UTC
Upstream is aware and working on it.
Comment 5 Thierry Carrez (RETIRED) gentoo-dev 2005-07-05 00:41:26 UTC
Upstream released fixed version 0.9.16.006
Comment 6 Aaron Walker (RETIRED) gentoo-dev 2005-07-06 03:21:00 UTC
In CVS.  amd64 and ppc please stable.
Comment 7 Aaron Walker (RETIRED) gentoo-dev 2005-07-06 03:23:00 UTC
Also, could whoever is the last arch to do it, please remove the two previous
versions (0.9.16.00[45])?
Comment 8 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-07-06 13:03:27 UTC
ppc done, blubb started with amd64
Comment 9 Simon Stelling (RETIRED) gentoo-dev 2005-07-06 13:21:27 UTC
amd64 stable; didn't remove old ebuilds yet since x86 is still testing
Comment 10 Simon Stelling (RETIRED) gentoo-dev 2005-07-06 13:27:15 UTC
old versions removed:

ka0ttic blubb: um there was never x86 stablew
ka0ttic certainly not going to mark it stable now
blubb i see
blubb ka0ttic: i'll remove the old versions then
ka0ttic blubb: thanks
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2005-07-06 13:40:06 UTC
Should be ready for GLSA
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-07-06 14:12:31 UTC
Waiting for egroupware to be ready for GLSA. 
Comment 13 Stefan Cornelius (RETIRED) gentoo-dev 2005-07-10 12:07:16 UTC
egroupware finally ready for GLSA -> this one is ready, too.
Comment 14 Matthias Geerdsen (RETIRED) gentoo-dev 2005-07-10 12:35:23 UTC
GLSA 200507-08

thanks everyone