Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 Buster DLA-3487-1 Moderate: Fusiondirectory XSS And Session Flaw

debian lts
Calendar Grey July 8, 2023
Dist Debian Esm H88
Ubuntu Security Notice USN-5001-1 has been released to tackle vulnerabilities in openldap, specifically CSRF and authentication weaknesses.
A potential Cross Site Scripting (XSS) vulnerablity (CVE-2022-36180) and session handling vulnerability (CVE-2022-36179 )have been found in fusiondirectory, a Web Based LDAP Admini...

Summary

Due to this, if CAS authentication is used, fusiondirectory
will stop working until those steps are done:

- make sure to install the updated fusiondirectory-schema package for
buster.

- update the fusiondirectory core schema in LDAP by running
fusiondirectory-insert-schema -m

- switch to using the new php-cas API by running
fusiondirectory-setup --set-config-CasLibraryBool=TRUE

- set the CAS ClientServiceName to the base URL of the fusiondirectory
installation, for example:
fusiondirectory-setup --set-config-CasClientServiceName=""


For Debian 10 buster, these problems have been fixed in version
1.2.3-4+deb10u2.

We recommend that you upgrade your fusiondirectory packages.

For the detailed security status of fusiondirectory please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/fusiondirectory

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be

Read the Full Advisory


-------------------------------------------------------------------------Package: fusiondirectory
Version: 1.2.3-4+deb10u2
CVE ID: CVE-2022-36179 CVE-2022-36180
Debian Bug:

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here