Source: phpsysinfo Version: 3.4.4-2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for phpsysinfo. CVE-2026-55584[0]: | phpSysInfo is a customizable PHP script that displays system | information. Prior to 3.4.6, the PSI_ALLOWED access-control check in | read_config.php trusts attacker-controlled X-Forwarded-For and | Client-IP HTTP headers before REMOTE_ADDR. A remote unauthenticated | attacker can supply an allowed address in one of these headers to | impersonate a trusted client and access exposed hostname, kernel, | CPU, memory, filesystem, and network-interface information. This | issue is fixed in version 3.4.6. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-55584 https://www.cve.org/CVERecord?id=CVE-2026-55584 [1] https://github.com/phpsysinfo/phpsysinfo/security/advisories/GHSA-786w-p5pm-cvgh [2] https://github.com/phpsysinfo/phpsysinfo/commit/019fa2d7e568ea11461adb4bd33da5dc87c4b9ab Please adjust the affected versions in the BTS as needed. Regards, Salvatore

