[CVE-2008-1502] XSS
Bug #212211 reported by
William Grant
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
egroupware (Debian) |
Fix Released
|
Unknown
|
|||
egroupware (Gentoo Linux) |
Fix Released
|
Low
|
|||
egroupware (Ubuntu) |
Fix Released
|
Undecided
|
William Grant | ||
Dapper |
Won't Fix
|
Undecided
|
Unassigned | ||
Edgy |
Won't Fix
|
Undecided
|
Unassigned | ||
Feisty |
Won't Fix
|
Undecided
|
Unassigned | ||
Gutsy |
Fix Released
|
Medium
|
Emanuele Gentili | ||
Hardy |
Fix Released
|
Undecided
|
William Grant |
Bug Description
Binary package hint: egroupware
"The _bad_protocol_once function in phpgwapi/
CVE References
Changed in egroupware: | |
assignee: | nobody → fujitsu |
status: | New → In Progress |
Changed in egroupware: | |
status: | Unknown → Confirmed |
Changed in egroupware: | |
status: | Unknown → Fix Released |
Changed in egroupware: | |
status: | Confirmed → In Progress |
Changed in egroupware: | |
status: | In Progress → Fix Released |
Changed in egroupware: | |
status: | In Progress → Fix Released |
Changed in egroupware (Gentoo Linux): | |
importance: | Unknown → Low |
To post a comment you must log in.
This bug was fixed in the package egroupware - 1.2.107- 2.dfsg- 2ubuntu1
--------------- 2.dfsg- 2ubuntu1) hardy; urgency=low
egroupware (1.2.107-
* SECURITY UPDATE: cross-site scripting via crafted URL protocols. patches/ CVE-2008- 1502.dpatch: Properly sanitise protocols in rField
(LP: #212211)
- debian/
URLs. Patch from upstream.
- References:
+ CVE-2008-1502
* Modify Maintainer value to match the DebianMaintaine
specification.
-- William Grant <email address hidden> Sat, 05 Apr 2008 22:47:05 +1100