Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
89

Fedora 32 - FEDORA-2020-c6fa47ecd7 Moderate: XSS Risk in phpldapadmin

Update to 1.2.6.2 (#1906752). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-c6fa47ecd7 2020-12-21 01:34:34.881730 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 32 Version : 1.2.6.2 Release : 1.fc32 URL : https://sourceforge.net/projects/phpldapadmin/ Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Update to 1.2.6.2 (#1906752) --------------------------------------------------------------------------------ChangeLog: * Fri Dec 11 2020 Dmitry Butskoy - 1.2.6.2-1 - Update to 1.2.6.2 (#1906752) * Tue Jul 28 2020 Fedora Release Engineering - 1.2.3-18 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1906752 - CVE-2020-35132 phpldapadmin: allows users to store malicious values which could result in XSS via get_request in lib/function.php https://bugzilla.redhat.com/show_bug.cgi?id=1906752 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-c6fa47ecd7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The release of phpldapadmin 1.2.6.2 on Fedora enhances protection from XSS vulnerabilities. Get it installed today!. phpldapadmin security, Fedora updates, XSS protection, web application security. . LinuxSecurity.com Team

Calendar 2 Dec 20, 2020 Fedora
89

Fedora 34: 2021-7ac1821d1f Critical: SQL Injection In Webmin Advisory

Update to 1.2.6.2 (#1906752). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-6cc5654c0e 2020-12-21 01:31:12.651546 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 33 Version : 1.2.6.2 Release : 1.fc33 URL : https://sourceforge.net/projects/phpldapadmin/ Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Update to 1.2.6.2 (#1906752) --------------------------------------------------------------------------------ChangeLog: * Fri Dec 11 2020 Dmitry Butskoy - 1.2.6.2-1 - Update to 1.2.6.2 (#1906752) --------------------------------------------------------------------------------References: [ 1 ] Bug #1906752 - CVE-2020-35132 phpldapadmin: allows users to store malicious values which could result in XSS via get_request in lib/function.php https://bugzilla.redhat.com/show_bug.cgi?id=1906752 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2020-6cc5654c0e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 33 has launched a new version of phpldapadmin addressing security vulnerabilities related to XSS, aimed at improving the administration of LDAP servers.. Fedora Update, XSS Vulnerability, phpldapadmin Tool. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 20, 2020 Critical Fedora
197

Debian 8: DLA-1561-1 Critical Phpldapadmin XSS Flaw Fix

It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for administering LDAP servers. For Debian 8 "Jessie", this problem has been fixed in version . Package : phpldapadmin Version : 1.2.2-5.2+deb8u1 CVE ID : CVE-2017-11107 Debian Bug : 867719 It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for administering LDAP servers. For Debian 8 "Jessie", this problem has been fixed in version 1.2.2-5.2+deb8u1. Note: the package changelog mistakenly refers to the non-existent CVE-2016-11107 identifier. The proper identifier to refer to this issue is CVE-2017-11107. We recommend that you upgrade your phpldapadmin packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- . Update phpldapadmin to version 1.2.2-5.2+deb8u1 to address an XSS vulnerability in Debian 8, enhancing the security posture.. phpldapadmin security update, Debian 8, XSS flaw. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 31, 2018 Critical Debian LTS
89

Fedora 25 Security Advisory: phpldapadmin XSS Critical Update

Fix CVE-2017-11107 (#1471112). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-346836a623 2017-07-24 17:29:46.084501 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 25 Version : 1.2.3 Release : 10.fc25 URL : https://sourceforge.net/projects/phpldapadmin/ Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Fix CVE-2017-11107 (#1471112) --------------------------------------------------------------------------------References: [ 1 ] Bug #1471112 - CVE-2017-11107 phpldapadmin: XSS in htdocs/entry_chooser.php via form, element, rdn, or container parameter https://bugzilla.redhat.com/show_bug.cgi?id=1471112 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade phpldapadmin' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora ProjectGPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Vital security patch for Fedora 25's phpldapadmin addresses XSS vulnerability, guaranteeing secure LDAP administration.. Fedora Security Update, phpldapadmin XSS, LDAP Management Tool. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 25, 2017 Critical Fedora
89

Fedora 24 Moderate: FEDORA-2017-1a8bebaab4 Phpldapadmin XSS Issue

Fix CVE-2017-11107 (#1471112). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-1a8bebaab4 2017-07-24 17:26:46.066484 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 24 Version : 1.2.3 Release : 10.fc24 URL : https://sourceforge.net/projects/phpldapadmin/ Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Fix CVE-2017-11107 (#1471112) --------------------------------------------------------------------------------References: [ 1 ] Bug #1471112 - CVE-2017-11107 phpldapadmin: XSS in htdocs/entry_chooser.php via form, element, rdn, or container parameter https://bugzilla.redhat.com/show_bug.cgi?id=1471112 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade phpldapadmin' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora ProjectGPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Phpldapadmin security notice for Fedora 24 addressing CVE-2017-11107. Crucial update to mitigate security vulnerabilities.. phpldapadmin security update, Fedora security advisory, LDAP management tool, XSS vulnerability fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 24, 2017 Important Fedora
89

Fedora 26: Update for Phpldapadmin Fixing Critical XSS Threat

Fix CVE-2017-11107 (#1471112). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-05888dd4fe 2017-07-24 17:28:25.943122 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 26 Version : 1.2.3 Release : 10.fc26 URL : / Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Fix CVE-2017-11107 (#1471112) --------------------------------------------------------------------------------References: [ 1 ] Bug #1471112 - CVE-2017-11107 phpldapadmin: XSS in htdocs/entry_chooser.php via form, element, rdn, or container parameter https://bugzilla.redhat.com/show_bug.cgi?id=1471112 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade phpldapadmin' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys usedby the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Important patch for Fedora 26 addressing XSS threat in phpldapadmin. Safeguard your system immediately.. Phpldapadmin Update,Fedora Security,Web Application Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 24, 2017 Critical Fedora
197

Debian 7: DLA-1019-1 Moderate: phpldapadmin XSS Vulnerability Fixed

It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for administering LDAP servers. For Debian 7 "Wheezy", this issue has been fixed in phpldapadmin version . Hash: SHA256 Package : phpldapadmin Version : 1.2.2-5+deb7u1 CVE ID : CVE-2017-11107 Debian Bug : #867719 It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for administering LDAP servers. For Debian 7 "Wheezy", this issue has been fixed in phpldapadmin version 1.2.2-5+deb7u1. We recommend that you upgrade your phpldapadmin packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Uncover the solution for a cross-site scripting vulnerability in phpldapadmin on Debian Wheezy, associated with security patch DLA-1019-1.. Debian LTS, XSS Vulnerability, phpldapadmin Update, LDAP Administration, Security Fix. . LinuxSecurity.com Team

Calendar 2 Jul 09, 2017 Debian LTS
87

Debian: DSA-2333-1 Critical PHP Code Execution Risk in Phpldapadmin

Two vulnerabilities have been discovered in phpldapadmin, a web based interface for administering LDAP servers. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory DSA-2333-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Jonathan Wiltshire Oct 31th, 2011 http://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : phpldapadmin Vulnerability : several Problem type : remote Debian-specific: no Debian bug : 646754 CVE IDs : CVE-2011-4075 CVE-2011-4074 Two vulnerabilities have been discovered in phpldapadmin, a web based interface for administering LDAP servers. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-4074 Input appended to the URL in cmd.php (when "cmd" is set to "_debug") is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. CVE-2011-4075 Input passed to the "orderby" parameter in cmd.php (when "cmd" is set to "query_engine", "query" is set to "none", and "search" is set to e.g. "1") is not properly sanitised in lib/functions.php before being used in a "create_function()" function call. This can be exploited to inject and execute arbitrary PHP code. For the oldstable distribution (lenny), these problems have been fixed in version 1.1.0.5-6+lenny2. For the stable distribution (squeeze), these problems have been fixed in version 1.2.0.5-2+squeeze1. For the testing distribution (wheezy), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 1.2.0.5-2.1. We recommend that you upgrade your phpldapadminpackages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent vulnerabilities in phpldapadmin expose users to potential remote code execution threats. It is imperative for all users to update to the most recent version without delay.. LDAP Administration, PHP Code Execution, Debian Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 30, 2011 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here