Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Fedora 21 GLPI Security Advisory: Privilege Escalation via POST Request

fedora
Calendar Grey April 5, 2015
Dist Fedora Esm H88
Mitigation for privilege amplification through manipulated POST submissions in GLPI on Fedora 21, targeting significant security vulnerabilities.
* Fix privilege escalation via user creation with a crafted POST request

Summary

GLPI is the Information Resource-Manager with an additional Administration-

Interface. You can use it to build up a database with an inventory for your

company (computer, software, printers...). It has enhanced functions to make

the daily life for the administrators easier, like a job-tracking-system with

mail-notification and methods to build a database with basic information

about your network-topology.

Update Information:

* Fix privilege escalation via user creation with a crafted POST request

Change Log

* Tue Mar 24 2015 Remi Collet - 0.84.8-4 - add security fix * Mon Dec 22 2014 Remi Collet - 0.84.8-3 - fix SQL Injection CVE-2014-9258

References


[ 1 ] Bug #1194196 - glpi: privilege escalation via user creation with a crafted POST request https://bugzilla.redhat.com/show_bug.cgi?id=1194196

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update glpi' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: glpi
Product: Fedora 21
Version: 0.84.8
Release: 4.fc21
Summary: Free IT asset management software

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here