Gentoo Archives: gentoo-announce

From: aliz@gentoo.org (Daniel Ahlberg)
To: gentoo-announce@g.o, bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com
Subject: [gentoo-announce] GLSA: horde (200309-02)
Date: Mon, 01 Sep 2003 14:21:06
Message-Id: 20030901142827.76AA69FBB1@noc.internal.fairytale.se
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200309-02
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : horde
9           SUMMARY : session hijacking
10              DATE : 2003-09-01 14:28 UTC
11           EXPLOIT : remote
12 VERSIONS AFFECTED : <vmware-workstation-4.0.2.5592
13     FIXED VERSION : >=vmware-workstation-4.0.2.5592
14               CVE :
15
16 - - - ---------------------------------------------------------------------
17
18 quote from advisory:
19 "An attacker could send an email to the victim who ago use of HORDE MTA
20 in order to push it to visit a website. The website in issue log all the
21 accesses and describe in the particular the origin of every victim."
22
23 Read the full advisory at:
24 http://marc.theaimsgroup.com/?l=bugtraq&m=106081310531567&w=2
25
26 SOLUTION
27
28 It is recommended that all Gentoo Linux users who are running
29 net-www/horde upgrade to horde-2.2.4_rc2 as follows:
30
31 emerge sync
32 emerge horde
33 emerge clean
34
35 - - - ---------------------------------------------------------------------
36 aliz@g.o - GnuPG key is available at http://dev.gentoo.org/~aliz
37 - - - ---------------------------------------------------------------------
38 -----BEGIN PGP SIGNATURE-----
39 Version: GnuPG v1.2.3 (GNU/Linux)
40
41 iD8DBQE/U1eLfT7nyhUpoZMRAvNIAJ9Ff+t+uJUvFK4pqP90o0WB+4rGZACeOpF7
42 XE4AIoGECKrbQd+oFcZrYpQ=
43 =wWs6
44 -----END PGP SIGNATURE-----