Security

NAVIGATION
CATEGORIES
REFERRENCE
LINKS
Home » Development Group »» Security
  • New phpLDAPadmin packages fix cross-site scripting

    0 answers - 2151 bytes - related search similar search Add To My Delicious Add To My Stumble Upon Add To My Google Mark Add To My Facebook Add To My Digg

    PGP SIGNED MESSAGE
    Hash: SHA1
    -
    Debian Security Advisory DSA 1057-1 security (AT) debian (DOT) org
    Martin Schulze
    May 15th, 2006
    -
    Package : phpldapadmin
    Vulnerability : missing input sanitising
    Problem type : remote
    Debian-specific: no
    CVE ID : CVE-2006-2016
    BugTraq ID : 17643
    Debian Bug : 365313
    Several cross-site scripting vulnerabilities have been discovered in
    phpLDAPadmin, a web based interface for administering LDAP servers,
    tha allows remote attackers to inject arbitrary web script or HTML.
    The old stable distribution (woody) does not contain phpldapadmin
    packages.
    For the stable distribution (sarge) these problems have been fixed in
    version 0.9.5-3sarge3.
    For the unstable distribution (sid) these problems have been fixed in
    version 0.9.8.3-1.
    We recommend that you upgrade your phpldapadmin package.
    Upgrade Instructions
    -
    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.
    If you are using the apt-get package manager, use the line for
    sources.list as given at the end of this advisory:
    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    Debian GNU/Linux 3.1 alias sarge
    -
    Source archives:
    Size/MD5 checksum: 619
    Size/MD5 checksum: 12460
    Size/MD5 checksum: 617707
    Architecture independent components:
    Size/MD5 checksum: 617970
    These files will probably be moved into the stable distribution on
    its next update.
    -
    For apt-get: deb http://security.debian.org/ stable/updates main
    For dpkg-ftp: dists/stable/updates/main
    Mailing list: debian-security-announce (AT) lists (DOT) debian.org
    Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
    PGP SIGNATURE
    Version: GnuPG v1.4.3 (GNU/Linux)
    L2keerjA1onNQ6yPaDChxwo=
    =I
    PGP SIGNATURE

Re: New phpLDAPadmin packages fix cross-site scripting


max 4000 letters.
Your nickname that display:
In order to stop the spam: 0 + 9 =
SPONSORED
QUESTION

SPONSORED
EMSDN