Jump to content

Security Advisory (MDKSA-2003:077): phpgroupware


aru
 Share

Recommended Posts

MandrakeSoft Security Advisory MDKSA-2003:077 : phpgroupware

 

July 23rd, 2003

Updated phpgroupware packages fix multiple vulnerabilities

 

Several vulnerabilities were discovered in all versions of phpgroupware prior to 0.9.14.006. This latest version fixes an exploitable condition in all versions that can be exploited remotely without authentication and can lead to arbitrary code execution on the web server. This vulnerability is being actively exploited.

 

Version 0.9.14.005 fixed several other vulnerabilities including cross-site scripting issues that can be exploited to obtain sensitive information such as authentication cookies.

 

This update provides the latest stable version of phpgroupware and all users are encouraged to update immediately. In addition, you should also secure your installation by including the following in your Apache configuration files:

 

Order allow,deny Deny from all

 

 

The released versions of Mandrake GNU/Linux affected are:

  • 8.2

 

[*] 9.0

 

[*] 9.1

 

[*] Corporate Server 2.1

Full information about this advisory, including the updated packages, is available at:

www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:077

 

Other references:

http://cve.mitre.org/cgi-bin/cvename.cgi?n...e=CAN-2003-0577

http://www.security-corporation.com/articl...030702-005.html

 

Posted automatically by aru (mdksec2mub v0.0.6)

Link to comment
Share on other sites

 Share

×
×
  • Create New...