|
|||||||||||
|
[SECURITY] [DSA 1389-1] New zoph packages fix SQL injection
From: Moritz Muehlenhoff <jmm(at)debian.org>
Date: Thu Oct 18 2007 - 16:39:48 EDT
Package : zoph Vulnerability : missing input sanitising Problem-Type : remote Debian-specific: no CVE ID : CVE-2007-3905 Debian Bug : 435711 It was discovered that zoph, a web based photo management system, performs insufficient input sanitising, which allows SQL injection. For the oldstable distribution (sarge) this problem has been fixed in version 0.3.3-12sarge2. For the stable distribution (etch) this problem has been fixed in version 0.6-2.1etch1. For the unstable distribution (sid) this problem has been fixed in version 0.7.0.2-1. We recommend that you upgrade your zoph package. Upgrade Instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives:
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.3.3-12sarge1.dsc
Size/MD5 checksum: 570 ce9957fa5af8115a5aec530aabe6847f
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.3.3-12sarge1.diff.gz
Size/MD5 checksum: 53959 7c37d28798981a054c634cca92122199
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.3.3.orig.tar.gz
Size/MD5 checksum: 153902 5ff9d8e182e16d53e0511b6d51da8521
Architecture independent components: http://security.debian.org/pool/updates/main/z/zoph/zoph_0.3.3-12sarge1_all.deb Size/MD5 checksum: 172190 a185b3cba99ea4bc0f46c73b68bb5a46 Debian GNU/Linux 4.0 alias etch - ------------------------------- Source archives:
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.6-2.1etch1.dsc
Size/MD5 checksum: 850 a7bf5364534ae9fb38ba70dcc371e8c6
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.6-2.1etch1.diff.gz
Size/MD5 checksum: 25826 c716e920cb6c9b19941af6359ecc697d
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.6.orig.tar.gz
Size/MD5 checksum: 382577 7e139b32bd477cccf43454cb4c07c16d
Architecture independent components: http://security.debian.org/pool/updates/main/z/zoph/zoph_0.6-2.1etch1_all.deb Size/MD5 checksum: 394268 147f75305b9b891fb2ab502a94be3e9e These files will probably be moved into the stable distribution on its next update.
iD8DBQFHF8RmXm3vHE4uyloRAg2WAKDcWvMUaZf1ahtha4yGGnBLN2bSFwCcCKcw
Z8I79ybTvjkGwBp2wveTmlA=
-- To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Thu Oct 18 16:45:39 2007 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:53:31 EDT |
||||||||||
|
|||||||||||