From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-200805-04.xml | 74 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 74 insertions(+) create mode 100644 metadata/glsa/glsa-200805-04.xml (limited to 'metadata/glsa/glsa-200805-04.xml') diff --git a/metadata/glsa/glsa-200805-04.xml b/metadata/glsa/glsa-200805-04.xml new file mode 100644 index 000000000000..d91a2213a94b --- /dev/null +++ b/metadata/glsa/glsa-200805-04.xml @@ -0,0 +1,74 @@ + + + + eGroupWare: Multiple vulnerabilities + + Multiple vulnerabilities in eGroupWare may lead to execution of arbitrary + PHP code, the ability to upload malicious files and cross-site scripting + attacks. + + egroupware + 2008-05-07 + 2008-05-07: 01 + 214212 + 218625 + remote + + + 1.4.004 + 1.4.004 + + + +

+ eGroupWare is a suite of web-based group applications including + calendar, address book, messenger and email. +

+
+ +

+ A vulnerability has been reported in FCKEditor due to the way that file + uploads are handled in the file + editor/filemanager/upload/php/upload.php when a filename has multiple + file extensions (CVE-2008-2041). Another vulnerability exists in the + _bad_protocol_once() function in the file + phpgwapi/inc/class.kses.inc.php, which allows remote attackers to + bypass HTML filtering (CVE-2008-1502). +

+
+ +

+ The first vulnerability can be exploited to upload malicious files and + execute arbitrary PHP code provided that a directory is writable by the + webserver. The second vulnerability can be exploited by remote + attackers via a specially crafted URL in order to conduct cross-site + scripting attacks. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ All eGroupWare users should upgrade to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-apps/egroupware-1.4.004" +
+ + CVE-2008-1502 + CVE-2008-2041 + + + keytoaster + + + mfleming + + + vorlon + +
-- cgit v1.2.3