Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in AWL
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in AWL
ID: USN-4539-1
Distribution: Ubuntu
Plattformen: Ubuntu 20.04 LTS
Datum: Do, 24. September 2020, 23:37
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11728
Applikationen: AWL

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============4063390407545686072==
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="DPz6Rd0jNWJm2MGqfuBMoLbvRuH2ldeks"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--DPz6Rd0jNWJm2MGqfuBMoLbvRuH2ldeks
Content-Type: multipart/mixed;
boundary="9QPIO4Cp1P5ulE0CaLtelkpmHezDDY6js"

--9QPIO4Cp1P5ulE0CaLtelkpmHezDDY6js
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable
Content-Language: en-US

==========================================================================
Ubuntu Security Notice USN-4539-1
September 24, 2020

awl vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

DAViCal Andrew's Web Libraries could be made to run programs as your login
if it received specially crafted input.

Software Description:
- awl: PHP Utility Libraries

Details:

Andrew Bartlett discovered that DAViCal Andrew's Web Libraries (AWL) did
not properly manage session keys. An attacker could possibly use this
issue to impersonate a session. (CVE-2020-11728)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
libawl-php 0.60-1+deb10u1ubuntu1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4539-1
CVE-2020-11728

Package Information:
https://launchpad.net/ubuntu/+source/awl/0.60-1+deb10u1ubuntu1



--9QPIO4Cp1P5ulE0CaLtelkpmHezDDY6js--

--DPz6Rd0jNWJm2MGqfuBMoLbvRuH2ldeks
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEElnO/d49FoUPK9fwytGdj0GOh2+wFAl9s+DIACgkQtGdj0GOh
2+y1kggAllCUcK8WZjy5ZSFTAX8XPEeHPvXt0sYL9MryaduSGkCdqXq5I4HA5QdY
u/Jvipj9XF9qUQmUGLiOwrhWzDE9Xg6Pa92DVgL069uQUE9D/6UBRfw3i3ZvYI7m
J3Y9Jn+imIpoyIRo/SmnPnP61w8tEMLk6q/Xaibw3o9l3I5DkdBm2rG09PcxsVJW
sjoNAlB8P+lQguPsPZDQushQglZlTTBpoxb/w8Rs866i7KTxcr/EvAOlR5MzQshu
1q1MHAL+H4fuP7ekPybPwie74rPmwSovLPRABL36A6ZO+j/K9dGS7yV5pvq5q2Bw
rVeTj9kbuWBOcUZ0ON9MEn7vtVWEJA==
=NO7R
-----END PGP SIGNATURE-----

--DPz6Rd0jNWJm2MGqfuBMoLbvRuH2ldeks--


--===============4063390407545686072==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============4063390407545686072==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung