Login
Newsletter
Werbung

Sicherheit: Cross-Site Scripting in phpldapadmin
Aktuelle Meldungen Distributionen
Name: Cross-Site Scripting in phpldapadmin
ID: FEDORA-2012-14363
Distribution: Fedora
Plattformen: Fedora 16
Datum: Sa, 6. Oktober 2012, 08:46
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1114
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1115
Applikationen: phpldapadmin

Originalnachricht

Name        : phpldapadmin
Product : Fedora 16
Version : 1.2.2
Release : 3.gitbbedf1.fc16
URL : http://phpldapadmin.sourceforge.net
Summary : Web-based tool for managing LDAP servers
Description :
PhpLDAPadmin is a web-based LDAP client.
It provides easy, anywhere-accessible, multi-language administration
for your LDAP server. Its hierarchical tree-viewer and advanced search
functionality make it intuitive to browse and administer your LDAP directory.

Since it is a web application, this LDAP browser works on many platforms,
making your LDAP server easily manageable from any location.

PhpLDAPadmin is the perfect LDAP browser for the LDAP professional
and novice alike. Its user base consists mostly of LDAP administration
professionals.

Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server
location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow
access by remote web-clients.

-------------------------------------------------------------------------------
-
Update Information:

fix CVE-2012-1114 and CVE-2012-1115
-------------------------------------------------------------------------------
-
ChangeLog:

* Tue Sep 18 2012 Dmitry Butskoy <Dmitry@Butskoy.name> -
1.2.2-3.gitbbedf1
- update to latest git source (CVE-2012-1114, CVE-2012-1115, #799873)
* Sat Jul 21 2012 Fedora Release Engineering
<rel-eng@lists.fedoraproject.org> - 1.2.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
* Thu Feb 2 2012 Dmitry Butskoy <Dmitry@Butskoy.name> - 1.2.2-1
- update to 1.2.2
- fix CVE-2012-0834 (#786821, patch from upstream)
* Sat Jan 14 2012 Fedora Release Engineering
<rel-eng@lists.fedoraproject.org> - 1.2.1.1-3.20111006git
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Tue Oct 25 2011 Dmitry Butskoy <Dmitry@Butskoy.name> -
1.2.1.1-2.20111006git
- update to the latest git #cddf783 to fix security issues
(XSS and code injection vulnerabilities, #748538)
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #799873 - CVE-2012-1114 CVE-2012-1115 phpldapadmin: XSS flaws via
'export', 'add_value_form' and 'dn' variables
https://bugzilla.redhat.com/show_bug.cgi?id=799873
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update phpldapadmin' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung