Sicherheit: Cross-Site Scripting in phpldapadmin
Aktuelle Meldungen Distributionen
Name: Cross-Site Scripting in phpldapadmin
ID: FEDORA-2017-346836a623
Distribution: Fedora
Plattformen: Fedora 25
Datum: Di, 25. Juli 2017, 07:13
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11107
Applikationen: phpldapadmin


Fedora Update Notification
2017-07-24 17:29:46.084501

Name : phpldapadmin
Product : Fedora 25
Version : 1.2.3
Release : 10.fc25
URL : http://phpldapadmin.sourceforge.net
Summary : Web-based tool for managing LDAP servers
Description :
PhpLDAPadmin is a web-based LDAP client.
It provides easy, anywhere-accessible, multi-language administration
for your LDAP server. Its hierarchical tree-viewer and advanced search
functionality make it intuitive to browse and administer your LDAP directory.

Since it is a web application, this LDAP browser works on many platforms,
making your LDAP server easily manageable from any location.

PhpLDAPadmin is the perfect LDAP browser for the LDAP professional
and novice alike. Its user base consists mostly of LDAP administration

Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server
location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow
access by remote web-clients.

Update Information:

Fix CVE-2017-11107 (#1471112)

[ 1 ] Bug #1471112 - CVE-2017-11107 phpldapadmin: XSS in
htdocs/entry_chooser.php via form, element, rdn, or container parameter

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade phpldapadmin' at the command line.
For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Unterstützer werden
Neue Nachrichten