Update to 1.2.6.2 (#1906752). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-c6fa47ecd7 2020-12-21 01:34:34.881730 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 32 Version : 1.2.6.2 Release : 1.fc32 URL : https://sourceforge.net/projects/phpldapadmin/ Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Update to 1.2.6.2 (#1906752) --------------------------------------------------------------------------------ChangeLog: * Fri Dec 11 2020 Dmitry Butskoy - 1.2.6.2-1 - Update to 1.2.6.2 (#1906752) * Tue Jul 28 2020 Fedora Release Engineering - 1.2.3-18 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1906752 - CVE-2020-35132 phpldapadmin: allows users to store malicious values which could result in XSS via get_request in lib/function.php https://bugzilla.redhat.com/show_bug.cgi?id=1906752 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-c6fa47ecd7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 1.2.6.2 (#1906752). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-6cc5654c0e 2020-12-21 01:31:12.651546 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 33 Version : 1.2.6.2 Release : 1.fc33 URL : https://sourceforge.net/projects/phpldapadmin/ Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Update to 1.2.6.2 (#1906752) --------------------------------------------------------------------------------ChangeLog: * Fri Dec 11 2020 Dmitry Butskoy - 1.2.6.2-1 - Update to 1.2.6.2 (#1906752) --------------------------------------------------------------------------------References: [ 1 ] Bug #1906752 - CVE-2020-35132 phpldapadmin: allows users to store malicious values which could result in XSS via get_request in lib/function.php https://bugzilla.redhat.com/show_bug.cgi?id=1906752 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2020-6cc5654c0e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for administering LDAP servers. For Debian 8 "Jessie", this problem has been fixed in version . Package : phpldapadmin Version : 1.2.2-5.2+deb8u1 CVE ID : CVE-2017-11107 Debian Bug : 867719 It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for administering LDAP servers. For Debian 8 "Jessie", this problem has been fixed in version 1.2.2-5.2+deb8u1. Note: the package changelog mistakenly refers to the non-existent CVE-2016-11107 identifier. The proper identifier to refer to this issue is CVE-2017-11107. We recommend that you upgrade your phpldapadmin packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- . Update phpldapadmin to version 1.2.2-5.2+deb8u1 to address an XSS vulnerability in Debian 8, enhancing the security posture.. phpldapadmin security update, Debian 8, XSS flaw. . Severity: Critical. LinuxSecurity.com Team
Fix CVE-2017-11107 (#1471112). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-346836a623 2017-07-24 17:29:46.084501 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 25 Version : 1.2.3 Release : 10.fc25 URL : https://sourceforge.net/projects/phpldapadmin/ Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Fix CVE-2017-11107 (#1471112) --------------------------------------------------------------------------------References: [ 1 ] Bug #1471112 - CVE-2017-11107 phpldapadmin: XSS in htdocs/entry_chooser.php via form, element, rdn, or container parameter https://bugzilla.redhat.com/show_bug.cgi?id=1471112 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade phpldapadmin' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora ProjectGPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Fix CVE-2017-11107 (#1471112). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-1a8bebaab4 2017-07-24 17:26:46.066484 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 24 Version : 1.2.3 Release : 10.fc24 URL : https://sourceforge.net/projects/phpldapadmin/ Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Fix CVE-2017-11107 (#1471112) --------------------------------------------------------------------------------References: [ 1 ] Bug #1471112 - CVE-2017-11107 phpldapadmin: XSS in htdocs/entry_chooser.php via form, element, rdn, or container parameter https://bugzilla.redhat.com/show_bug.cgi?id=1471112 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade phpldapadmin' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora ProjectGPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Fix CVE-2017-11107 (#1471112). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-05888dd4fe 2017-07-24 17:28:25.943122 --------------------------------------------------------------------------------Name : phpldapadmin Product : Fedora 26 Version : 1.2.3 Release : 10.fc26 URL : / Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. --------------------------------------------------------------------------------Update Information: Fix CVE-2017-11107 (#1471112) --------------------------------------------------------------------------------References: [ 1 ] Bug #1471112 - CVE-2017-11107 phpldapadmin: XSS in htdocs/entry_chooser.php via form, element, rdn, or container parameter https://bugzilla.redhat.com/show_bug.cgi?id=1471112 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade phpldapadmin' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys usedby the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for administering LDAP servers. For Debian 7 "Wheezy", this issue has been fixed in phpldapadmin version . Hash: SHA256 Package : phpldapadmin Version : 1.2.2-5+deb7u1 CVE ID : CVE-2017-11107 Debian Bug : #867719 It was discovered that there was a cross-site scripting (XSS) vulnerability in phpldapadmin, a web-based interface for administering LDAP servers. For Debian 7 "Wheezy", this issue has been fixed in phpldapadmin version 1.2.2-5+deb7u1. We recommend that you upgrade your phpldapadmin packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Two vulnerabilities have been discovered in phpldapadmin, a web based interface for administering LDAP servers. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory DSA-2333-1
Get the latest Linux and open source security news straight to your inbox.