OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA16232] Debian update for phpbb2

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Thu Jul 28 2005 - 02:21:16 CDT


----------------------------------------------------------------------

Bist Du interessiert an einem neuen Job in IT-Sicherheit?

Secunia hat zwei freie Stellen als Junior und Senior Spezialist in IT-
Sicherheit:
http://secunia.com/secunia_vacancies/

----------------------------------------------------------------------

TITLE:
Debian update for phpbb2

SECUNIA ADVISORY ID:
SA16232

VERIFY ADVISORY:
http://secunia.com/advisories/16232/

CRITICAL:
Moderately critical

IMPACT:
Cross Site Scripting

WHERE:
From remote

OPERATING SYSTEM:
Debian GNU/Linux 3.1
http://secunia.com/product/5307/
Debian GNU/Linux unstable alias sid
http://secunia.com/product/530/

DESCRIPTION:
Debian has issued an update for phpbb2. This fixes a vulnerability,
which can be exploited by malicious people to conduct script
insertion attacks.

For more information:
SA16149

SOLUTION:
Apply updated packages.

-- Debian GNU/Linux 3.1 --

Source archives:

http://security.debian.org/pool/updates/main/p/phpbb2/phpbb2_2.0.13+1-6sarge1.dsc
Size/MD5 checksum: 783 a2192409bb6c743be83d87529e00ebcc
http://security.debian.org/pool/updates/main/p/phpbb2/phpbb2_2.0.13+1-6sarge1.diff.gz
Size/MD5 checksum: 61579 e5a598478e4f01a3e8981b72c1356445
http://security.debian.org/pool/updates/main/p/phpbb2/phpbb2_2.0.13+1.orig.tar.gz
Size/MD5 checksum: 3340445 678d0cb0372e46402a472c510fb90d78

Architecture independent components:

http://security.debian.org/pool/updates/main/p/phpbb2/phpbb2-conf-mysql_2.0.13-6sarge1_all.deb
Size/MD5 checksum: 36996 9d27f1ba0c529544447be2537a2e427c
http://security.debian.org/pool/updates/main/p/phpbb2/phpbb2-languages_2.0.13-6sarge1_all.deb
Size/MD5 checksum: 2868362 8de633213b53ff0c2029b0b3e28aa847
http://security.debian.org/pool/updates/main/p/phpbb2/phpbb2_2.0.13-6sarge1_all.deb
Size/MD5 checksum: 525020 2e0d83079efc4321532e062a4c746598

-- Debian GNU/Linux unstable alias sid --

Fixed in version 2.0.13-6sarge1.

ORIGINAL ADVISORY:
http://www.debian.org/security/2005/dsa-768

OTHER REFERENCES:
SA16149:
http://secunia.com/advisories/16149/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------