Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 251037 (CVE-2008-6506) - <www-apps/phpBB-3.0.4: Multiple vulnerabilities (CVE-2008-{6506,6507})
Summary: <www-apps/phpBB-3.0.4: Multiple vulnerabilities (CVE-2008-{6506,6507})
Status: RESOLVED FIXED
Alias: CVE-2008-6506
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/33166/
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-12-15 15:05 UTC by Bruno Buss
Modified: 2009-03-24 20:29 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bruno Buss 2008-12-15 15:05:21 UTC
Description:
A security issue has been reported in phpBB, which can be exploited by malicious users to bypass certain security restrictions.

The application does not properly restrict access to the functionality required to activate deactivated accounts. This can be exploited to re-activate deactivated accounts without the required privileges.


Solution:
Update to version 3.0.4
Comment 1 Gunnar Wrobel (RETIRED) gentoo-dev 2008-12-28 21:12:38 UTC
Added www-apps/phpBB-3.0.4, removed vulnerable version 3.0.2 and 3.0.3. Unstable on all archs. webapps done.
Comment 2 Bruno Buss 2008-12-28 22:06:28 UTC
All done, closing the bug.
Comment 3 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-03-24 20:29:06 UTC
CVE-2008-6506 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6506):
  Unspecified vulnerability in phpBB before 3.0.4 allows attackers to
  bypass intended access restrictions and activate de-activated
  accounts via unknown vectors.

CVE-2008-6507 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-6507):
  Unspecified vulnerability in phpBB before 3.0.4 allows attackers to
  obtain sensitive information via unknown vectors related to the lack
  of password prompts for a private message that quotes a post in a
  password-protected forum.