- ------------------------------------------------------------------------Debian Security Advisory DSA-1568-1                  security@debian.org
http://www.debian.org/security/                          Thijs Kinkhorst
May 05, 2008                          http://www.debian.org/security/faq
- ------------------------------------------------------------------------Package        : b2evolution
Vulnerability  : insufficient input sanitising
Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2007-0175
Debian Bug     : 410568

"unsticky" discovered that b2evolution, a blog engine, performs
insufficient input sanitising, allowing for cross site scripting.

For the stable distribution (etch), this problem has been fixed in
version 0.9.2-3+etch1.

For the unstable distribution (sid), this problem has been fixed in
version 0.9.2-4.

We recommend that you upgrade your b2evolution (0.9.2-3+etch1) package.

Upgrade instructions
- --------------------wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 4.0 alias etch
- -------------------------------Source archives:

      Size/MD5 checksum:    14774 0513ba676280c394ab9494ccdfea35e5
      Size/MD5 checksum:  2754129 6014a784ecc92a3a875e7ac69939047b
      Size/MD5 checksum:      882 3938cec5016aa5ac8c838ee668121832

Architecture independent packages:

      Size/MD5 checksum:  2818756 6174d72fee72c0f6ff6e4221344799cc


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp:  dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org

Debian: New b2evolution packages fix cross site scripting

May 5, 2008
"unsticky" discovered that b2evolution, a blog engine, performs insufficient input sanitising, allowing for cross site scripting.

Summary

Severity

Related News