- - - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200306-15
- - - ---------------------------------------------------------------------

          PACKAGE : phpbb
          SUMMARY : sql injection
             DATE : 2003-06-28 20:22 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : =phpbb-2.0.5
              CVE : CAN-2003-0486

- - - ---------------------------------------------------------------------

quote from cve:
"SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and 
earlier allows remote attackers to steal password hashes via the 
topic_id parameter."

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-www/phpbb upgrade to phpbb-2.0.5 as follows

emerge sync
emerge phpbb
emerge clean

- - - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at   
robbat2@gentoo.org
- - - ---------------------------------------------------------------------

Gentoo: phpbb SQL injection vulnerability

QL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.

Summary


GENTOO LINUX SECURITY ANNOUNCEMENT 200306-15


quote from cve: "SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter."
SOLUTION
It is recommended that all Gentoo Linux users who are running net-www/phpbb upgrade to phpbb-2.0.5 as follows
emerge sync emerge phpbb emerge clean
aliz@gentoo.org - GnuPG key is available at robbat2@gentoo.org

Resolution

References

Availability

Concerns

Severity
PACKAGE : phpbb
SUMMARY : sql injection
DATE : 2003-06-28 20:22 UTC
EXPLOIT : remote
VERSIONS AFFECTED : =phpbb-2.0.5
CVE : CAN-2003-0486

Synopsis

Background

Affected Packages

Impact

Workaround

Related News