Mandrake Linux Security Advisory : phpgroupware (MDKSA-2003:077)

medium Nessus Plugin ID 14060

Synopsis

The remote Mandrake Linux host is missing a security update.

Description

Several vulnerabilities were discovered in all versions of phpgroupware prior to 0.9.14.006. This latest version fixes an exploitable condition in all versions that can be exploited remotely without authentication and can lead to arbitrary code execution on the web server. This vulnerability is being actively exploited.

Version 0.9.14.005 fixed several other vulnerabilities including cross-site scripting issues that can be exploited to obtain sensitive information such as authentication cookies.

This update provides the latest stable version of phpgroupware and all users are encouraged to update immediately. In addition, you should also secure your installation by including the following in your Apache configuration files :

<Directory /var/www/html/phpgroupware> <Files ~ '.inc.php$'> Order allow,deny Deny from all </Files> </Directory>

Solution

Update the affected phpgroupware package.

See Also

http://www.security-corporation.com/

Plugin Details

Severity: Medium

ID: 14060

File Name: mandrake_MDKSA-2003-077.nasl

Version: 1.23

Type: local

Published: 7/31/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:phpgroupware, cpe:/o:mandrakesoft:mandrake_linux:8.2, cpe:/o:mandrakesoft:mandrake_linux:9.0, cpe:/o:mandrakesoft:mandrake_linux:9.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 7/23/2003

Reference Information

CVE: CVE-2003-0504

MDKSA: 2003:077