Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201811-05 ] PHProjekt: Multiple vulnerabilities
Date: Sat, 10 Nov 2018 00:23:51
Message-Id: 93958ce2-f58d-e8f8-1af8-c0f5462ad15a@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201811-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: PHProjekt: Multiple vulnerabilities
9 Date: November 10, 2018
10 Bugs: #650936
11 ID: 201811-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in PHProjekt due to embedded
19 Zend Framework, the worst of which could allow attackers to remotely
20 execute arbitrary commands.
21
22 Background
23 ==========
24
25 PHProjekt is an application suite that supports communication and
26 management of teams and companies.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 www-apps/phprojekt <= 6.1.2 Vulnerable!
35 -------------------------------------------------------------------
36 NOTE: Certain packages are still vulnerable. Users should migrate
37 to another package if one is available or wait for the
38 existing packages to be marked stable by their
39 architecture maintainers.
40
41 Description
42 ===========
43
44 Multiple vulnerabilities have been discovered in PHProjekt due to
45 embedded Zend Framework. Please review the GLSA identifiers referenced
46 below for details.
47
48 Impact
49 ======
50
51 Remote attackers could execute arbitrary commands or conduct SQL
52 injection attacks.
53
54 Workaround
55 ==========
56
57 There is no known workaround at this time.
58
59 Resolution
60 ==========
61
62 Gentoo has discontinued support for PHProjekt and recommends that users
63 unmerge the package:
64
65 # emerge --unmerge "www-apps/phprojekt"
66
67 References
68 ==========
69
70 [ 1 ] GLSA 201804-10
71 https://security.gentoo.org/glsa/201804-10
72
73 Availability
74 ============
75
76 This GLSA and any updates to it are available for viewing at
77 the Gentoo Security Website:
78
79 https://security.gentoo.org/glsa/201811-05
80
81 Concerns?
82 =========
83
84 Security is a primary focus of Gentoo Linux and ensuring the
85 confidentiality and security of our users' machines is of utmost
86 importance to us. Any security concerns should be addressed to
87 security@g.o or alternatively, you may file a bug at
88 https://bugs.gentoo.org.
89
90 License
91 =======
92
93 Copyright 2018 Gentoo Foundation, Inc; referenced text
94 belongs to its owner(s).
95
96 The contents of this document are licensed under the
97 Creative Commons - Attribution / Share Alike license.
98
99 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature