Gentoo Archives: gentoo-announce

From: Raphael Marichez <falco@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200706-07 ] PHProjekt: Multiple vulnerabilities
Date: Tue, 19 Jun 2007 22:16:27
Message-Id: 20070619215917.GD13743@falco.falcal.net
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200706-07
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: PHProjekt: Multiple vulnerabilities
9 Date: June 19, 2007
10 Bugs: #170905
11 ID: 200706-07
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been discovered in PHProjekt, allowing
19 for the execution of arbitrary PHP and SQL code, and cross-site
20 scripting attacks.
21
22 Background
23 ==========
24
25 PHProjekt is a project management and coordination tool written in PHP.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 www-apps/phprojekt < 5.2.1 >= 5.2.1
34
35 Description
36 ===========
37
38 Alexios Fakos from n.runs AG has discovered multiple vulnerabilities in
39 PHProjekt, including the execution of arbitrary SQL commands using
40 unknown vectors (CVE-2007-1575), the execution of arbitrary PHP code
41 using an unrestricted file upload (CVE-2007-1639), cross-site request
42 forgeries using different modules (CVE-2007-1638), and a cross-site
43 scripting attack using unkown vectors (CVE-2007-1576).
44
45 Impact
46 ======
47
48 An authenticated user could elevate their privileges by exploiting the
49 vulnerabilities described above. Note that the magic_quotes_gpc PHP
50 configuration setting must be set to "off" to exploit these
51 vulnerabilities.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 All PHProjekt users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=www-apps/phprojekt-5.2.1"
65
66 References
67 ==========
68
69 [ 1 ] CVE-2007-1575
70 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1575
71 [ 2 ] CVE-2007-1576
72 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1576
73 [ 3 ] CVE-2007-1638
74 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1638
75 [ 4 ] CVE-2007-1639
76 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1639
77
78 Availability
79 ============
80
81 This GLSA and any updates to it are available for viewing at
82 the Gentoo Security Website:
83
84 http://security.gentoo.org/glsa/glsa-200706-07.xml
85
86 Concerns?
87 =========
88
89 Security is a primary focus of Gentoo Linux and ensuring the
90 confidentiality and security of our users machines is of utmost
91 importance to us. Any security concerns should be addressed to
92 security@g.o or alternatively, you may file a bug at
93 http://bugs.gentoo.org.
94
95 License
96 =======
97
98 Copyright 2007 Gentoo Foundation, Inc; referenced text
99 belongs to its owner(s).
100
101 The contents of this document are licensed under the
102 Creative Commons - Attribution / Share Alike license.
103
104 http://creativecommons.org/licenses/by-sa/2.5