LWN.net Logo

egroupware: denial of service

Package(s):egroupware CVE #(s):CVE-2008-2041 CVE-2008-1502
Created:May 8, 2008 Updated:July 18, 2008
Description: From the Gentoo alert:

A vulnerability has been reported in FCKEditor due to the way that file uploads are handled in the file editor/filemanager/upload/php/upload.php when a filename has multiple file extensions (CVE-2008-2041). Another vulnerability exists in the _bad_protocol_once() function in the file phpgwapi/inc/class.kses.inc.php, which allows remote attackers to bypass HTML filtering (CVE-2008-1502).

Alerts:
SuSE SUSE-SR:2008:015 2008-07-18
Fedora FEDORA-2008-6226 2008-07-09
Gentoo 200805-04 2008-05-07

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds