Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: DSA 419-1 Critical: PHPGroupWare Remote Execution and SQL Injection

debian
Calendar Grey January 9, 2004
Debian Logo
Addressing critical phpgroupware weaknesses within Debian: inadequate processes and possible SQL breaches require immediate intervention.
Improper remote execution and SQL code injection issues.

Summary

The authors of phpgroupware, a web based groupware system written in
PHP, discovered several vulnerabilities. The Common Vulnerabilities
and Exposures project identifies the following problems:

CAN-2004-0016

In the "calendar" module, "save extension" was not enforced for
holiday files. As a result, server-side php scripts may be placed
in directories that then could be accessed remotely and cause the
webserver to execute those. This was resolved by enforcing the
extension ".txt" for holiday files.

CAN-2004-0017

Some SQL injection problems (non-escaping of values used in SQL
strings) the "calendar" and "infolog" modules.

Additionally, the Debian maintainer adjusted the permissions on world
writable directories that were accidently created by former postinst
during the installation.

For the stable distribution (woody) this problem has been fixed in
version 0.9.14-0.RC3.2.woody3.

For the unstable distribution (sid) this problem has been fixed in
version 0.9.14.007-4.

We recommend that yo...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: phpgroupware
CVE ID: CAN-2004-0016 CAN-2004-0017

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here