LWN.net Logo

WebCalendar: multiple vulnerabilities

Package(s):WebCalendar CVE #(s):
Created:August 5, 2013 Updated:August 7, 2013
Description: From the WebCalendar bug report:

Version 1.2.7 (22 Jan 2013)

  • Security fix: Do not show the reason for a failed login (i.e. "no such user")
  • Security fix: Escape HTML characters in category name.
  • Security fix: Check all passed in fields (either via HTML form or via URL parameter) for certain malicious tags (script, embed, etc.) and generate fatal error if found.
Alerts:
Fedora FEDORA-2013-13484 2013-08-02
Fedora FEDORA-2013-13454 2013-08-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds