LWN.net Logo

Fedora alert FEDORA-2012-14344 (phpldapadmin)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 17 Update: phpldapadmin-1.2.2-3.gitbbedf1.fc17
Date:  Sat, 06 Oct 2012 03:44:27 +0000
Message-ID:  <20121006034427.D1CF220A22@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2012-14344 2012-09-19 02:31:10 -------------------------------------------------------------------------------- Name : phpldapadmin Product : Fedora 17 Version : 1.2.2 Release : 3.gitbbedf1.fc17 URL : http://phpldapadmin.sourceforge.net Summary : Web-based tool for managing LDAP servers Description : PhpLDAPadmin is a web-based LDAP client. It provides easy, anywhere-accessible, multi-language administration for your LDAP server. Its hierarchical tree-viewer and advanced search functionality make it intuitive to browse and administer your LDAP directory. Since it is a web application, this LDAP browser works on many platforms, making your LDAP server easily manageable from any location. PhpLDAPadmin is the perfect LDAP browser for the LDAP professional and novice alike. Its user base consists mostly of LDAP administration professionals. Edit /etc/phpldapadmin/config.php to change default (localhost) LDAP server location and other things. Edit /etc/httpd/conf.d/phpldapadmin.conf to allow access by remote web-clients. -------------------------------------------------------------------------------- Update Information: fix CVE-2012-1114 and CVE-2012-1115 -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 18 2012 Dmitry Butskoy <Dmitry@Butskoy.name> - 1.2.2-3.gitbbedf1 - update to latest git source (CVE-2012-1114, CVE-2012-1115, #799873) * Sat Jul 21 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #799873 - CVE-2012-1114 CVE-2012-1115 phpldapadmin: XSS flaws via 'export', 'add_value_form' and 'dn' variables https://bugzilla.redhat.com/show_bug.cgi?id=799873 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update phpldapadmin' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds