Your message dated Wed, 23 Nov 2005 14:02:40 -0800
with message-id <[EMAIL PROTECTED]>
and subject line Bug#340094: fixed in phpgroupware 0.9.16.009-1
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--------------------------------------
Received: (at submit) by bugs.debian.org; 20 Nov 2005 21:41:23 +0000
>From [EMAIL PROTECTED] Sun Nov 20 13:41:23 2005
Return-path: <[EMAIL PROTECTED]>
Received: from inutil.org ([193.22.164.111]
helo=vserver151.vserver151.serverflex.de)
by spohr.debian.org with esmtp (Exim 4.50)
id 1Edww6-00058O-W5
for [EMAIL PROTECTED]; Sun, 20 Nov 2005 13:41:23 -0800
Received: from dslb-082-083-203-033.pools.arcor-ip.net ([82.83.203.33]
helo=localhost.localdomain)
by vserver151.vserver151.serverflex.de with esmtpsa
(TLS-1.0:RSA_AES_256_CBC_SHA:32)
(Exim 4.50)
id 1Edww5-00018b-Oz
for [EMAIL PROTECTED]; Sun, 20 Nov 2005 22:41:21 +0100
Received: from jmm by localhost.localdomain with local (Exim 4.54)
id 1Edwvy-0001aj-JQ; Sun, 20 Nov 2005 22:41:15 +0100
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Moritz Muehlenhoff <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: CVE-2005-2781: Execution of arbitrary web code
X-Mailer: reportbug 3.17
Date: Sun, 20 Nov 2005 22:41:14 +0100
X-Debbugs-Cc: Debian Security Team <[EMAIL PROTECTED]>
Message-Id: <[EMAIL PROTECTED]>
X-SA-Exim-Connect-IP: 82.83.203.33
X-SA-Exim-Mail-From: [EMAIL PROTECTED]
X-SA-Exim-Scanned: No (on vserver151.vserver151.serverflex.de); SAEximRunCond
expanded to false
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level:
X-Spam-Status: No, hits=-10.5 required=4.0 tests=BAYES_00,HAS_PACKAGE,
RCVD_IN_SORBS,X_DEBBUGS_CC autolearn=ham
version=2.60-bugs.debian.org_2005_01_02
Package: phpgroupware-fudforum
Severity: grave
Tags: security
Justification: user security hole
phpgroupware embeds a shared/forked copy of "fudforum", which was
vulnerable to:
| The Avatar upload feature in FUD Forum before 2.7.0 does not properly
| verify uploaded files, which allows remote attackers to execute arbitrary
| PHP code via a file with a .php extension that contains image data
| followed by PHP code.
(Please see http://secunia.com/advisories/16627/ for details)
phpgroupware-fudforum is vulnerable as well, see
http://www.mail-archive.com/[email protected]/msg21210.html for a
fix.
Cheers,
Moritz
-- System Information:
Debian Release: testing/unstable
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: i386 (i686)
Shell: /bin/sh linked to /bin/bash
Kernel: Linux 2.6.14-2-686
Locale: LANG=C, [EMAIL PROTECTED] (charmap=ISO-8859-15)
---------------------------------------
Received: (at 340094-close) by bugs.debian.org; 23 Nov 2005 22:12:08 +0000
>From [EMAIL PROTECTED] Wed Nov 23 14:12:08 2005
Return-path: <[EMAIL PROTECTED]>
Received: from katie by spohr.debian.org with local (Exim 4.50)
id 1Ef2hM-0006d9-Ls; Wed, 23 Nov 2005 14:02:40 -0800
From: Thomas Viehmann <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
X-Katie: $Revision: 1.56 $
Subject: Bug#340094: fixed in phpgroupware 0.9.16.009-1
Message-Id: <[EMAIL PROTECTED]>
Sender: Archive Administrator <[EMAIL PROTECTED]>
Date: Wed, 23 Nov 2005 14:02:40 -0800
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level:
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER
autolearn=no version=2.60-bugs.debian.org_2005_01_02
Source: phpgroupware
Source-Version: 0.9.16.009-1
We believe that the bug you reported is fixed in the latest version of
phpgroupware, which is due to be installed in the Debian FTP archive:
phpgroupware-addressbook_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-addressbook_0.9.16.009-1_all.deb
phpgroupware-admin_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-admin_0.9.16.009-1_all.deb
phpgroupware-bookmarks_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-bookmarks_0.9.16.009-1_all.deb
phpgroupware-calendar_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-calendar_0.9.16.009-1_all.deb
phpgroupware-chat_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-chat_0.9.16.009-1_all.deb
phpgroupware-comic_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-comic_0.9.16.009-1_all.deb
phpgroupware-developer-tools_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-developer-tools_0.9.16.009-1_all.deb
phpgroupware-dj_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-dj_0.9.16.009-1_all.deb
phpgroupware-eldaptir_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-eldaptir_0.9.16.009-1_all.deb
phpgroupware-email_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-email_0.9.16.009-1_all.deb
phpgroupware-etemplate_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-etemplate_0.9.16.009-1_all.deb
phpgroupware-felamimail_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-felamimail_0.9.16.009-1_all.deb
phpgroupware-filemanager_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-filemanager_0.9.16.009-1_all.deb
phpgroupware-folders_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-folders_0.9.16.009-1_all.deb
phpgroupware-ftp_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-ftp_0.9.16.009-1_all.deb
phpgroupware-fudforum_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-fudforum_0.9.16.009-1_all.deb
phpgroupware-headlines_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-headlines_0.9.16.009-1_all.deb
phpgroupware-hr_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-hr_0.9.16.009-1_all.deb
phpgroupware-img_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-img_0.9.16.009-1_all.deb
phpgroupware-infolog_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-infolog_0.9.16.009-1_all.deb
phpgroupware-manual_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-manual_0.9.16.009-1_all.deb
phpgroupware-messenger_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-messenger_0.9.16.009-1_all.deb
phpgroupware-news-admin_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-news-admin_0.9.16.009-1_all.deb
phpgroupware-nntp_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-nntp_0.9.16.009-1_all.deb
phpgroupware-notes_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-notes_0.9.16.009-1_all.deb
phpgroupware-phonelog_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-phonelog_0.9.16.009-1_all.deb
phpgroupware-phpbrain_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-phpbrain_0.9.16.009-1_all.deb
phpgroupware-phpgwapi_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-phpgwapi_0.9.16.009-1_all.deb
phpgroupware-phpsysinfo_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-phpsysinfo_0.9.16.009-1_all.deb
phpgroupware-polls_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-polls_0.9.16.009-1_all.deb
phpgroupware-preferences_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-preferences_0.9.16.009-1_all.deb
phpgroupware-projects_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-projects_0.9.16.009-1_all.deb
phpgroupware-qmailldap_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-qmailldap_0.9.16.009-1_all.deb
phpgroupware-registration_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-registration_0.9.16.009-1_all.deb
phpgroupware-setup_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-setup_0.9.16.009-1_all.deb
phpgroupware-sitemgr_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-sitemgr_0.9.16.009-1_all.deb
phpgroupware-skel_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-skel_0.9.16.009-1_all.deb
phpgroupware-soap_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-soap_0.9.16.009-1_all.deb
phpgroupware-stocks_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-stocks_0.9.16.009-1_all.deb
phpgroupware-todo_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-todo_0.9.16.009-1_all.deb
phpgroupware-tts_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-tts_0.9.16.009-1_all.deb
phpgroupware-wiki_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-wiki_0.9.16.009-1_all.deb
phpgroupware-xmlrpc_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware-xmlrpc_0.9.16.009-1_all.deb
phpgroupware_0.9.16.009-1.diff.gz
to pool/main/p/phpgroupware/phpgroupware_0.9.16.009-1.diff.gz
phpgroupware_0.9.16.009-1.dsc
to pool/main/p/phpgroupware/phpgroupware_0.9.16.009-1.dsc
phpgroupware_0.9.16.009-1_all.deb
to pool/main/p/phpgroupware/phpgroupware_0.9.16.009-1_all.deb
phpgroupware_0.9.16.009.orig.tar.gz
to pool/main/p/phpgroupware/phpgroupware_0.9.16.009.orig.tar.gz
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Viehmann <[EMAIL PROTECTED]> (supplier of updated phpgroupware package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Wed, 23 Nov 2005 20:48:29 +0100
Source: phpgroupware
Binary: phpgroupware-stocks phpgroupware-skel phpgroupware-email
phpgroupware-sitemgr phpgroupware-admin phpgroupware-etemplate
phpgroupware-notes phpgroupware-hr phpgroupware-qmailldap
phpgroupware-preferences phpgroupware-fudforum phpgroupware-felamimail
phpgroupware-headlines phpgroupware-infolog phpgroupware-news-admin
phpgroupware-img phpgroupware-developer-tools phpgroupware-nntp
phpgroupware-chat phpgroupware-messenger phpgroupware-projects phpgroupware-ftp
phpgroupware-polls phpgroupware-dj phpgroupware-xmlrpc phpgroupware-bookmarks
phpgroupware-manual phpgroupware-calendar phpgroupware-phpsysinfo
phpgroupware-phpbrain phpgroupware-filemanager phpgroupware-eldaptir
phpgroupware-phonelog phpgroupware-registration phpgroupware-folders
phpgroupware-setup phpgroupware-phpgwapi phpgroupware-comic
phpgroupware-addressbook phpgroupware phpgroupware-todo phpgroupware-tts
phpgroupware-wiki phpgroupware-soap
Architecture: source all
Version: 0.9.16.009-1
Distribution: unstable
Urgency: high
Maintainer: Thomas Viehmann <[EMAIL PROTECTED]>
Changed-By: Thomas Viehmann <[EMAIL PROTECTED]>
Description:
phpgroupware - web based groupware system written in PHP
phpgroupware-addressbook - phpGroupWare addressbook management module
phpgroupware-admin - phpGroupWare administration module
phpgroupware-bookmarks - phpGroupWare bookmark management module
phpgroupware-calendar - phpGroupWare calendar management module
phpgroupware-chat - phpGroupWare chat module
phpgroupware-comic - phpGroupWare comic strip parser module
phpgroupware-developer-tools - phpGroupWare developer tools
phpgroupware-dj - phpGroupWare mp3 database interface module
phpgroupware-eldaptir - phpGroupWare LDAP tree editor module
phpgroupware-email - phpGroupWare E-Mail client module
phpgroupware-etemplate - phpGroupWare etemplate module
phpgroupware-felamimail - phpGroupWare felamimail (Squirrelmail) module
phpgroupware-filemanager - phpGroupWare filemanager module
phpgroupware-folders - phpGroupWare folders module
phpgroupware-ftp - phpGroupWare ftp module
phpgroupware-fudforum - phpGroupWare fudforum module
phpgroupware-headlines - phpGroupWare headlines catcher module
phpgroupware-hr - phpGroupWare human resource management module
phpgroupware-img - phpGroupWare image editor module
phpgroupware-infolog - phpGroupWare infolog applcation
phpgroupware-manual - phpGroupWare on-line manual module
phpgroupware-messenger - phpGroupWare messenger module
phpgroupware-news-admin - phpGroupWare news administration interface
phpgroupware-nntp - phpGroupWare newsgroup reader module
phpgroupware-notes - phpGroupWare notes management module
phpgroupware-phonelog - phpGroupWare phone logging module
phpgroupware-phpbrain - phpGroupWare phpbrain module
phpgroupware-phpgwapi - library of common phpGroupWare functions
phpgroupware-phpsysinfo - phpGroupWare phpSysInfo module
phpgroupware-polls - phpGroupWare polling module
phpgroupware-preferences - phpGroupWare preferences management module
phpgroupware-projects - phpGroupWare projects management module
phpgroupware-qmailldap - phpGroupWare qmailldap module
phpgroupware-registration - phpGroupWare registration module
phpgroupware-setup - phpGroupWare setup III module
phpgroupware-sitemgr - phpGroupWare web content manager
phpgroupware-skel - phpGroupWare skeleton module
phpgroupware-soap - phpGroupWare SOAP module
phpgroupware-stocks - phpGroupWare stock management module
phpgroupware-todo - phpGroupWare todo list management module
phpgroupware-tts - phpGroupWare tts module
phpgroupware-wiki - phpGroupWare wiki module
phpgroupware-xmlrpc - phpGroupWare XMLRPC module
Closes: 340094
Changes:
phpgroupware (0.9.16.009-1) unstable; urgency=high
.
* New upstream release
* Features security fix to fudforum (scripting files could be uploaded
using the avatar image feature), CAN-2005-2781. Closes: #340094.
Files:
7f9ead2bcd59f7a8d629a8fbfb234288 1612 web optional
phpgroupware_0.9.16.009-1.dsc
142188c7dd30d5a1a2190ba0995ae2dd 19176672 web optional
phpgroupware_0.9.16.009.orig.tar.gz
1de7435606d56ebdce656e4bc5ac569a 35944 web optional
phpgroupware_0.9.16.009-1.diff.gz
2c86a62a593d588dd6cc8f84263dc58d 161136 web optional
phpgroupware_0.9.16.009-1_all.deb
596d07f624e8d1c38047c29f0f72f0a0 180666 web optional
phpgroupware-addressbook_0.9.16.009-1_all.deb
2e92bd0a7a7022fd938ad575d8b32d61 193736 web optional
phpgroupware-admin_0.9.16.009-1_all.deb
e0e96ba2a3abb065e92054e755d9aa20 103012 web optional
phpgroupware-bookmarks_0.9.16.009-1_all.deb
c71a030f84e9f61d6f6ba554603961b5 335876 web optional
phpgroupware-calendar_0.9.16.009-1_all.deb
50bb3dda57904875e800a0158bbeb975 23720 web optional
phpgroupware-chat_0.9.16.009-1_all.deb
7d0deebd4964387a8c1d098debf4a7b1 435202 web optional
phpgroupware-comic_0.9.16.009-1_all.deb
2c3c07dd9513fd7a48340817e28e3b27 44208 web optional
phpgroupware-dj_0.9.16.009-1_all.deb
b0f5c626c56aa3b31dba286e5428592d 51296 web optional
phpgroupware-eldaptir_0.9.16.009-1_all.deb
a2e73ec625930fec9975f6712460b771 1137752 web optional
phpgroupware-email_0.9.16.009-1_all.deb
b8c018072bd3753c9a220e8d2887b63c 184486 web optional
phpgroupware-felamimail_0.9.16.009-1_all.deb
9d055d8f04d7e53517bd0d2c3a7a3ca7 37256 web optional
phpgroupware-ftp_0.9.16.009-1_all.deb
4266d6ea8f7949f04ca1ef98f0133995 64904 web optional
phpgroupware-headlines_0.9.16.009-1_all.deb
d46cb091b27d71be6cfffc9a35524184 19372 web optional
phpgroupware-hr_0.9.16.009-1_all.deb
b429e752245c386cc690e2a07408351c 9032 web optional
phpgroupware-img_0.9.16.009-1_all.deb
a93ba0a36494bc853cb7e15a7acf3879 141060 web optional
phpgroupware-infolog_0.9.16.009-1_all.deb
ec0928be53a36642b564c512f6d66ef2 91094 web optional
phpgroupware-manual_0.9.16.009-1_all.deb
8ec5f069fcb962c2ccb3df01631d1890 26842 web optional
phpgroupware-messenger_0.9.16.009-1_all.deb
48a14c546dcdce67b2cddc68c2b49bb8 47664 web optional
phpgroupware-nntp_0.9.16.009-1_all.deb
a72cdc8074ac6d515746ee461d003554 35718 web optional
phpgroupware-notes_0.9.16.009-1_all.deb
6ccdab28198914af36c53e91bef22c75 21222 web optional
phpgroupware-phonelog_0.9.16.009-1_all.deb
c2bd77f9cb50644f269a4281ca6a2db4 9428416 web optional
phpgroupware-phpgwapi_0.9.16.009-1_all.deb
d2b11732a8222dc5dcd58a50325d1bf1 116908 web optional
phpgroupware-phpsysinfo_0.9.16.009-1_all.deb
ce48a0118fd1ab7a8a404f3fde2db5bd 32534 web optional
phpgroupware-polls_0.9.16.009-1_all.deb
4e55412f3fac4ba93bdd282229e3b7eb 63016 web optional
phpgroupware-preferences_0.9.16.009-1_all.deb
b3a3fe2a1f6d8b1c6437d2241ff9e215 125576 web optional
phpgroupware-projects_0.9.16.009-1_all.deb
126f975b87866d7843894f26cc6832d5 31056 web optional
phpgroupware-registration_0.9.16.009-1_all.deb
32702a5e368a963f69d93195205b78ec 278652 web optional
phpgroupware-setup_0.9.16.009-1_all.deb
f987c60b103bc2de1d55b60aab2c4f2b 19580 web optional
phpgroupware-skel_0.9.16.009-1_all.deb
89b1d92fd9afb171e13e14c525441955 24444 web optional
phpgroupware-soap_0.9.16.009-1_all.deb
1397f41d6dbde8613eca5b7b270a4c5d 22540 web optional
phpgroupware-stocks_0.9.16.009-1_all.deb
65dbe508c5bc87e60330e79c39de2188 52246 web optional
phpgroupware-todo_0.9.16.009-1_all.deb
43b75f01f2214821ad94238fd134bda7 63898 web optional
phpgroupware-xmlrpc_0.9.16.009-1_all.deb
e9c3be0bda94c777b179f923645dd7b4 35620 web optional
phpgroupware-developer-tools_0.9.16.009-1_all.deb
ea80168cfe53ea9710eafabe72fa2706 42762 web optional
phpgroupware-news-admin_0.9.16.009-1_all.deb
33361afbf243ae4e14b4b0adcd15cbd1 911314 web optional
phpgroupware-sitemgr_0.9.16.009-1_all.deb
050a620165c2247f502ce900247fa35d 1334214 web optional
phpgroupware-etemplate_0.9.16.009-1_all.deb
a49341fa59b8e6e93e16770d2de94593 95198 web optional
phpgroupware-filemanager_0.9.16.009-1_all.deb
e14c36a072707f0efe2c8600e0e9db9b 166820 web optional
phpgroupware-folders_0.9.16.009-1_all.deb
1c8b890e323c7d9ffe53da5a012cf946 1359678 web optional
phpgroupware-fudforum_0.9.16.009-1_all.deb
32417474992ce9c5a96ea8a8a81357d9 41868 web optional
phpgroupware-phpbrain_0.9.16.009-1_all.deb
95787518ba59dff63c0b0515592939bb 24462 web optional
phpgroupware-qmailldap_0.9.16.009-1_all.deb
c3f03fbbab61d50de805deec4922b5ec 57810 web optional
phpgroupware-tts_0.9.16.009-1_all.deb
d7bd86f1f106d95d9d08f18251a6017f 70892 web optional
phpgroupware-wiki_0.9.16.009-1_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)
Comment: GnuPG key at <http://thomas.viehmann.net/>
iD8DBQFDhNJMriZpaaIa1PkRAtBeAJ9ef6mpq16cVuxBj41w9qfRos42CgCfYQT1
6Fm2z6wipYBvnOREHrgPsKU=
=wlSM
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]