Gentoo Archives: gentoo-announce

From: "Christopher Díaz Riveros" <chrisadr@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201711-12 ] eGroupWare: Remote code execution
Date: Sun, 12 Nov 2017 22:41:24
Message-Id: 1510526417.29347.26.camel@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory                           GLSA 201711-12
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4                                            https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7  Severity: Normal
8     Title: eGroupWare: Remote code execution
9      Date: November 12, 2017
10      Bugs: #501908
11        ID: 201711-12
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in eGroupWare, the worst of
19 which allows remote attackers to execute arbitrary code.
20
21 Background
22 ==========
23
24 eGroupWare is a suite of web-based group applications including
25 calendar, address book, messenger and email.
26
27 Affected packages
28 =================
29
30     -------------------------------------------------------------------
31      Package              /     Vulnerable     /            Unaffected
32     -------------------------------------------------------------------
33   1  www-apps/egroupware     < 1.8.004.20120613                   >=  
34
35 Description
36 ===========
37
38 It was found that eGroupWare contains multiple code injection
39 vulnerabilities in multiple parameters and routes because of improper
40 input sanitization.
41
42 Impact
43 ======
44
45 A remote attacker could execute arbitrary code, delete arbitrary files
46 or inject arbitrary PHP objects via multiple routes.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 Gentoo has discontinued support for SquirrelMail and recommends that
57 users unmerge the package:
58
59   # emerge --unmerge "www-apps/egroupware"
60
61 References
62 ==========
63
64 [ 1 ] CVE-2014-2027
65       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2027
66
67 Availability
68 ============
69
70 This GLSA and any updates to it are available for viewing at
71 the Gentoo Security Website:
72
73  https://security.gentoo.org/glsa/201711-12
74
75 Concerns?
76 =========
77
78 Security is a primary focus of Gentoo Linux and ensuring the
79 confidentiality and security of our users' machines is of utmost
80 importance to us. Any security concerns should be addressed to
81 security@g.o or alternatively, you may file a bug at
82 https://bugs.gentoo.org.
83
84 License
85 =======
86
87 Copyright 2017 Gentoo Foundation, Inc; referenced text
88 belongs to its owner(s).
89
90 The contents of this document are licensed under the
91 Creative Commons - Attribution / Share Alike license.
92
93 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature