Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Debian: DSA-2333-1 Critical PHP Code Execution Risk in Phpldapadmin

debian
Calendar Grey October 30, 2011
Scroller Debian
Recent vulnerabilities in phpldapadmin expose users to potential remote code execution threats. It is imperative for all users to update to the most recent version without delay.
Two vulnerabilities have been discovered in phpldapadmin, a web based interface for administering LDAP servers

Summary

Two vulnerabilities have been discovered in phpldapadmin, a web based
interface for administering LDAP servers. The Common Vulnerabilities and
Exposures project identifies the following problems:

CVE-2011-4074

Input appended to the URL in cmd.php (when "cmd" is set to "_debug") is
not properly sanitised before being returned to the user. This can be
exploited to execute arbitrary HTML and script code in a user's browser
session in context of an affected site.

CVE-2011-4075

Input passed to the "orderby" parameter in cmd.php (when "cmd" is set to
"query_engine", "query" is set to "none", and "search" is set to e.g.
"1") is not properly sanitised in lib/functions.php before being used in a
"create_function()" function call. This can be exploited to inject and
execute arbitrary PHP code.


For the oldstable distribution (lenny), these problems have been fixed in
version 1.1.0.5-6+lenny2.

For the stable distribution (squeeze), these problems have been fixed in
version 1.2.0.5-2+squeeze1.

F...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: phpldapadmin

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.