Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: phpbb (200306-15)
Date: Sat, 28 Jun 2003 20:35:32
Message-Id: 20030628202210.BA1A933747@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200306-15
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : phpbb
9           SUMMARY : sql injection
10              DATE : 2003-06-28 20:22 UTC
11           EXPLOIT : remote
12 VERSIONS AFFECTED : <phpbb-2.0.5
13     FIXED VERSION : >=phpbb-2.0.5
14               CVE : CAN-2003-0486
15
16 - - - ---------------------------------------------------------------------
17
18 quote from cve:
19 "SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and
20 earlier allows remote attackers to steal password hashes via the
21 topic_id parameter."
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running
26 net-www/phpbb upgrade to phpbb-2.0.5 as follows
27
28 emerge sync
29 emerge phpbb
30 emerge clean
31
32 - - - ---------------------------------------------------------------------
33 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
34 robbat2@g.o
35 - - - ---------------------------------------------------------------------
36 -----BEGIN PGP SIGNATURE-----
37 Version: GnuPG v1.2.2 (GNU/Linux)
38
39 iD8DBQE+/fjyfT7nyhUpoZMRAq+RAJ4r4fijIo8hJaEJq/p0DIgeRoAobQCeJBQr
40 to/2NXfPD4yTEGDjhd+B4EQ=
41 =Ybzs
42 -----END PGP SIGNATURE-----