[Secure-testing-team] Bug#588038: Directory traversal flaw by editing and saving list entries via php-admin web interface
Moritz Muehlenhoff
jmm at debian.org
Sun Jul 4 11:19:19 UTC 2010
Package: mlmmj
Severity: grave
Tags: security
Hi,
please see
http://www.openwall.com/lists/oss-security/2010/06/23/5
https://bugzilla.redhat.com/show_bug.cgi?id=607256
Proposed patch by upstream:
http://www.openwall.com/lists/oss-security/2010/06/26/1
This is CVE-2009-4896.
Cheers,
Moritz
-- System Information:
Debian Release: squeeze/sid
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.32-5-686 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15 at euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash
Versions of packages mlmmj depends on:
ii dctrl-tools 2.14 Command-line tools to process Debi
ii debconf [debconf-2.0] 1.5.32 Debian configuration management sy
ii exim4-daemon-light [mail-tran 4.71-4 lightweight Exim MTA (v4) daemon
ii libc6 2.10.2-9 Embedded GNU C Library: Shared lib
mlmmj recommends no packages.
Versions of packages mlmmj suggests:
pn mlmmj-php-web <none> (no description available)
pn mlmmj-php-web-admin <none> (no description available)
More information about the Secure-testing-team
mailing list