Gentoo Archives: gentoo-announce

From: aliz@gentoo.org (Daniel Ahlberg)
To: gentoo-announce@g.o, bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com
Subject: [gentoo-announce] GLSA: horde (200309-02.1)
Date: Mon, 01 Sep 2003 14:55:27
Message-Id: 20030901143823.EDF689FBB1@noc.internal.fairytale.se
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200309-02.1
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : horde
9           SUMMARY : session hijacking
10              DATE : 2003-09-01 14:38 UTC
11           EXPLOIT : remote
12 VERSIONS AFFECTED : <horde-2.2.4_rc2
13     FIXED VERSION : >=horde-2.2.4_rc2
14               CVE :
15
16 - - - ---------------------------------------------------------------------
17
18 This advisory contains the correct values for VERSIONS AFFECTED and
19 FIXED VERSION
20
21 SOLUTION
22
23 It is recommended that all Gentoo Linux users who are running
24 net-www/horde upgrade to horde-2.2.4_rc2 as follows:
25
26 emerge sync
27 emerge horde
28 emerge clean
29
30 - - - ---------------------------------------------------------------------
31 aliz@g.o - GnuPG key is available at http://dev.gentoo.org/~aliz
32 - - - ---------------------------------------------------------------------
33 -----BEGIN PGP SIGNATURE-----
34 Version: GnuPG v1.2.3 (GNU/Linux)
35
36 iD8DBQE/U1nffT7nyhUpoZMRAtETAKCyC3/tqrqGE0+ez6KoJZq9H3QiiwCgqXGy
37 HwJEzyCYBJBWgt6FxFXFkKc=
38 =jCBY
39 -----END PGP SIGNATURE-----