Maksymilian Arciemowicz discoverd several cross site scripting
problems, of which not all were fixed in DSA 724.
CVE-2005-3347
Christopher Kunz discovered that local variables get overwritten
unconditionally and are trusted later, which could lead to the
inclusion of arbitrary files.
CVE-2005-3348
Christopher Kunz discovered that user-supplied input is used
unsanitised, causing a HTTP Response splitting problem.
For the old stable distribution (woody) these problems have been fixed in
version 0.9.14-0.RC3.2.woody5.
For the stable distribution (sarge) these problems have been fixed in
version 0.9.16.005-3.sarge4.
For the unstable distribution (sid) these problems have been fixed in
version 0.9.16.008-2.
We recommend that you upgrade your phpgroupware packages.
Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package man...
Get the latest Linux and open source security news straight to your inbox.