Collabtive could be made to run programs if it received specially crafted network traffic from an authenticated user.. =========================================================================Ubuntu Security Notice USN-4590-1 October 19, 2020 collabtive vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Collabtive could be made to run programs if it received specially crafted network traffic from an authenticated user. Software Description: - collabtive: Web-based project management software Details: It was discovered that Collabtive did not properly validate avatar image file uploads. An authenticated user could exploit this with a crafted file to cause Collabtive to execute arbitrary code. (CVE-2015-0258) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: collabtive 2.0+dfsg-6ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4590-1 CVE-2015-0258 Package Information: https://launchpad.net/ubuntu/+source/collabtive/2.0+dfsg-6ubuntu1.1 . Ubuntu Security Notice USN-4590-1 addresses a security flaw in Collabtive impacting 16.04 LTS. Patches have been provided.. ubuntu security, collabtive vulnerability, software update, security notice, CVE-2015-0258. . LinuxSecurity.com Team
An issue has been found in collabtive, a web-based project management software. Due to missing checks an attacker could upload scripts, which would execute code on the server by accessing for example avatar images. . Package : collabtive Version : 2.0+dfsg-5+deb8u1 CVE ID : CVE-2015-0258 An issue has been found in collabtive, a web-based project management software. Due to missing checks an attacker could upload scripts, which would execute code on the server by accessing for example avatar images. For Debian 8 "Jessie", this problem has been fixed in version 2.0+dfsg-5+deb8u1. We recommend that you upgrade your collabtive packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Essential collaborative enhancement addresses script running vulnerability following recent security breach. Update immediately to protect your system.. collabtive security, web management software, abuse protection, Debian advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.