Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Gentoo: GLSA-200406-09 High: Horde-Chora Remote Command Execution

gentoo
Calendar Grey June 15, 2004
Dist Gentoo Esm H88
An important security flaw in Chora on Gentoo allows for unauthorized code execution; users are urged to update to version 1.2.2 or later.
A vulnerability in Chora allows remote code execution and file upload.

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200406-09
                                            https://security.gentoo.org/

Severity: High Title: Horde-Chora: Remote code execution Date: June 15, 2004 Bugs: #53800 ID: 200406-09

Synopsis ======= A vulnerability in Chora allows remote code execution and file upload.
Background ========= Chora is a PHP-based SVN/CVS repository viewer by the HORDE project.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-www/horde-chora < 1.2.2 >= 1.2.2
========== A vulnerability in the diff viewer of Chora allows an attacker to inject shellcode. An attacker can exploit PHP's file upload functionality to upload a malicio...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3604476_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here