Bug#504255: CVE-2007-3215: remote shell command execution in class.phpmailer.php

2009-10-20 Thread Olivier Berger
FYI, a patch has been included in recent upload of phpgroupware (1:0.9.16.012+dfsg-9) in order to fix the code although it is normally not used. Best regards, -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#504255: CVE-2007-3215: remote shell command execution in class.phpmailer.php

2008-11-02 Thread Raphael Geissert
Package: phpgroupware-felamimail Severity: grave Version: 0.9.16.011-2.2 Tags: security patch Hi, The following CVE (Common Vulnerabilities Exposures) id was published for PHPMailer, which affects the embedded copy shipped in phpgroupware-felamimail[0]. CVE-2007-3215[1]: PHPMailer 1.7, when

Bug#504255: CVE-2007-3215: remote shell command execution in class.phpmailer.php

2008-11-02 Thread Olivier Berger
Le dimanche 02 novembre 2008 à 00:56 -0600, Raphael Geissert a écrit : Hi, The following CVE (Common Vulnerabilities Exposures) id was published for PHPMailer, which affects the embedded copy shipped in phpgroupware-felamimail[0]. CVE-2007-3215[1]: PHPMailer 1.7, when configured to

Bug#504255: CVE-2007-3215: remote shell command execution in class.phpmailer.php

2008-11-02 Thread Olivier Berger
Le dimanche 02 novembre 2008 à 11:13 +0100, Olivier Berger a écrit : Thanks for spotting this problem. The referred [2] patch is actually not exactly apllicable to the version of class.phpmailer.php shipped in phpgroupware 0.9.11, and the correct one is attached. I'll try and work on

Bug#504255: CVE-2007-3215: remote shell command execution in class.phpmailer.php

2008-11-02 Thread Olivier Berger
Le dimanche 02 novembre 2008 à 00:56 -0600, Raphael Geissert a écrit : However, it would be better if phpgroupware-felamimail just depended on libphp-phpmailer (also available in etch) and the include/require calls changed to use the copy provided by that package, to avoid shipping yet