[Secure-testing-team] Bug#588038: Directory traversal flaw by editing and saving list entries via php-admin web interface

Moritz Muehlenhoff jmm at debian.org
Sun Jul 4 11:19:19 UTC 2010


Package: mlmmj
Severity: grave
Tags: security

Hi,
please see 
http://www.openwall.com/lists/oss-security/2010/06/23/5
https://bugzilla.redhat.com/show_bug.cgi?id=607256

Proposed patch by upstream:
http://www.openwall.com/lists/oss-security/2010/06/26/1

This is CVE-2009-4896.

Cheers,
        Moritz

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.32-5-686 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15 at euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages mlmmj depends on:
ii  dctrl-tools                   2.14       Command-line tools to process Debi
ii  debconf [debconf-2.0]         1.5.32     Debian configuration management sy
ii  exim4-daemon-light [mail-tran 4.71-4     lightweight Exim MTA (v4) daemon
ii  libc6                         2.10.2-9   Embedded GNU C Library: Shared lib

mlmmj recommends no packages.

Versions of packages mlmmj suggests:
pn  mlmmj-php-web                 <none>     (no description available)
pn  mlmmj-php-web-admin           <none>     (no description available)





More information about the Secure-testing-team mailing list