Several security issues were fixed in gosa.. =========================================================================Ubuntu Security Notice USN-4609-1 October 28, 2020 gosa vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in gosa. Software Description: - gosa: Web Based LDAP Administration Program Details: Fabian Henneke discovered that GOsa incorrectly handled client cookies. An authenticated user could exploit this with a crafted cookie to perform file deletions in the context of the user account that runs the web server. (CVE-2019-14466) It was discovered that GOsa incorrectly handled user access control. A remote attacker could use this issue to log into any account with a username containing the word "success". (CVE-2019-11187) Fabian Henneke discovered that GOsa was vulnerable to cross-site scripting attacks via the change password form. A remote attacker could use this flaw to run arbitrary web scripts. (CVE-2018-1000528) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: gosa 2.7.4+reloaded2-9ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4609-1 CVE-2018-1000528, CVE-2019-11187, CVE-2019-14466 Package Information: https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1 . Important security patch for gosa on Ubuntu, targeting various flaws and possible remote exploitation.. gosa vulnerabilities, Ubuntu security issues, XSS attacks, access control flaws, cookie handling vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program. . Package : gosa Version : 2.7.4+reloaded2-1+deb8u3 CVE ID : CVE-2018-1000528 Debian Bug : 902723 Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program. For Debian 8 "Jessie", this problem has been fixed in version 2.7.4+reloaded2-1+deb8u3. We recommend that you upgrade your gosa packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program. For the stable distribution (stretch), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4239-1
Get the latest Linux and open source security news straight to your inbox.