Otkrivene su dvije ranjivosti paketa phpldapadmin koje udaljeni napadač može iskoristiti za umetanje HTML i skriptnog koda, ili za pokretanje proizvoljnog PHP koda.
Paket: | phpldapadmin 1.x |
Operacijski sustavi: | Fedora 14, Fedora 15, Fedora 16 |
Kritičnost: | 7.5 |
Problem: | pogreška u programskoj funkciji, XSS |
Iskorištavanje: | udaljeno |
Posljedica: | proizvoljno izvršavanje programskog koda, umetanje HTML i skriptnog koda |
Rješenje: | programska zakrpa proizvođača |
CVE: | CVE-2011-4074, CVE-2011-4075 |
Izvorni ID preporuke: | FEDORA-2011-14986 |
Izvor: | Fedora |
Problem: | |
Sigurnosni propusti posljedica su pogrešaka u datoteci "cmd.php" i funkciji "masort" u "lib/functions.php". |
|
Posljedica: | |
Navedeni propusti mogu biti iskorišteni za XSS napad ili za pokretanje proizvoljnog PHP koda. |
|
Rješenje: | |
Svim korisnicima se savjetuje korištenje programske nadogradnje koja otklanja opisane propuste. |
Izvorni tekst preporuke
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-14986
2011-10-27 03:28:30
--------------------------------------------------------------------------------
Name : phpldapadmin
Product : Fedora 14
Version : 1.2.1.1
Release : 2.20111006git.fc14
URL : http://phpldapadmin.sourceforge.net
Summary : Web-based tool for managing LDAP servers
Description :
PhpLDAPadmin is a web-based LDAP client.
It provides easy, anywhere-accessible, multi-language administration
for your LDAP server. Its hierarchical tree-viewer and advanced search
functionality make it intuitive to browse and administer your LDAP directory.
Since it is a web application, this LDAP browser works on many platforms,
making your LDAP server easily manageable from any location.
PhpLDAPadmin is the perfect LDAP browser for the LDAP professional
and novice alike. Its user base consists mostly of LDAP administration
professionals.
Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server
location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow
access by remote web-clients.
--------------------------------------------------------------------------------
Update Information:
Update to the latest upstream development code to fix
CVE-2011-4074 and CVE-2011-4075 (XSS and code injection vulnerabilities in
versions <= 1.2.1.1)
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 25 2011 Dmitry Butskoy <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.2.1.1-2.20111006git
- update to the latest git #cddf783 to fix security issues
(XSS and code injection vulnerabilities, #748538)
* Fri Jul 22 2011 Dmitry Butskoy <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.2.1.1-1
- update to 1.2.1.1
* Wed Feb 9 2011 Fedora Release Engineering <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> -
1.2.0.5-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #748537 - CVE-2011-4074 CVE-2011-4075 phpldapadmin: XSS and code
injection vulnerabilities in <= 1.2.1.1
https://bugzilla.redhat.com/show_bug.cgi?id=748537
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update phpldapadmin' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-14993
2011-10-27 03:28:52
--------------------------------------------------------------------------------
Name : phpldapadmin
Product : Fedora 15
Version : 1.2.1.1
Release : 2.20111006git.fc15
URL : http://phpldapadmin.sourceforge.net
Summary : Web-based tool for managing LDAP servers
Description :
PhpLDAPadmin is a web-based LDAP client.
It provides easy, anywhere-accessible, multi-language administration
for your LDAP server. Its hierarchical tree-viewer and advanced search
functionality make it intuitive to browse and administer your LDAP directory.
Since it is a web application, this LDAP browser works on many platforms,
making your LDAP server easily manageable from any location.
PhpLDAPadmin is the perfect LDAP browser for the LDAP professional
and novice alike. Its user base consists mostly of LDAP administration
professionals.
Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server
location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow
access by remote web-clients.
--------------------------------------------------------------------------------
Update Information:
Update to the latest upstream development code to fix
CVE-2011-4074 and CVE-2011-4075 (XSS and code injection vulnerabilities in
versions <= 1.2.1.1)
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 25 2011 Dmitry Butskoy <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.2.1.1-2.20111006git
- update to the latest git #cddf783 to fix security issues
(XSS and code injection vulnerabilities, #748538)
* Fri Jul 22 2011 Dmitry Butskoy <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.2.1.1-1
- update to 1.2.1.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #748537 - CVE-2011-4074 CVE-2011-4075 phpldapadmin: XSS and code
injection vulnerabilities in <= 1.2.1.1
https://bugzilla.redhat.com/show_bug.cgi?id=748537
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update phpldapadmin' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-14924
2011-10-25 21:41:13
--------------------------------------------------------------------------------
Name : phpldapadmin
Product : Fedora 16
Version : 1.2.1.1
Release : 2.20111006git.fc16
URL : http://phpldapadmin.sourceforge.net
Summary : Web-based tool for managing LDAP servers
Description :
PhpLDAPadmin is a web-based LDAP client.
It provides easy, anywhere-accessible, multi-language administration
for your LDAP server. Its hierarchical tree-viewer and advanced search
functionality make it intuitive to browse and administer your LDAP directory.
Since it is a web application, this LDAP browser works on many platforms,
making your LDAP server easily manageable from any location.
PhpLDAPadmin is the perfect LDAP browser for the LDAP professional
and novice alike. Its user base consists mostly of LDAP administration
professionals.
Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server
location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow
access by remote web-clients.
--------------------------------------------------------------------------------
Update Information:
Update to the latest upstream development code to fix
CVE-2011-4074 and CVE-2011-4075 (XSS and code injection vulnerabilities in
versions <= 1.2.1.1)
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 25 2011 Dmitry Butskoy <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 1.2.1.1-2.20111006git
- update to the latest git #cddf783 to fix security issues
(XSS and code injection vulnerabilities, #748538)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #748537 - CVE-2011-4074 CVE-2011-4075 phpldapadmin: XSS and code
injection vulnerabilities in <= 1.2.1.1
https://bugzilla.redhat.com/show_bug.cgi?id=748537
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update phpldapadmin' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke