Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[SECURITY] [DSA 1389-1] New zoph packages fix SQL injection

From: Moritz Muehlenhoff <jmm(at)debian.org>
Date: Thu Oct 18 2007 - 16:39:48 EDT


-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

Package        : zoph
Vulnerability  : missing input sanitising
Problem-Type   : remote
Debian-specific: no
CVE ID         : CVE-2007-3905
Debian Bug     : 435711

It was discovered that zoph, a web based photo management system, performs insufficient input sanitising, which allows SQL injection.

For the oldstable distribution (sarge) this problem has been fixed in version 0.3.3-12sarge2.

For the stable distribution (etch) this problem has been fixed in version 0.6-2.1etch1.

For the unstable distribution (sid) this problem has been fixed in version 0.7.0.2-1.

We recommend that you upgrade your zoph package.

Upgrade Instructions

- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for sources.list as given below:

Do you need help?X

apt-get update

        will update the internal database apt-get upgrade

        will install corrected packages

You may use an automated update by adding the resources from the footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge

- --------------------------------

  Source archives:

    
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.3.3-12sarge1.dsc
      Size/MD5 checksum:      570 ce9957fa5af8115a5aec530aabe6847f
    
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.3.3-12sarge1.diff.gz
      Size/MD5 checksum:    53959 7c37d28798981a054c634cca92122199
    
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.3.3.orig.tar.gz
      Size/MD5 checksum:   153902 5ff9d8e182e16d53e0511b6d51da8521

  Architecture independent components:

    http://security.debian.org/pool/updates/main/z/zoph/zoph_0.3.3-12sarge1_all.deb       Size/MD5 checksum: 172190 a185b3cba99ea4bc0f46c73b68bb5a46

Do you need more help?X

Debian GNU/Linux 4.0 alias etch

- -------------------------------

  Source archives:

    
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.6-2.1etch1.dsc
      Size/MD5 checksum:      850 a7bf5364534ae9fb38ba70dcc371e8c6
    
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.6-2.1etch1.diff.gz
      Size/MD5 checksum:    25826 c716e920cb6c9b19941af6359ecc697d
    
http://security.debian.org/pool/updates/main/z/zoph/zoph_0.6.orig.tar.gz
      Size/MD5 checksum:   382577 7e139b32bd477cccf43454cb4c07c16d

  Architecture independent components:

    http://security.debian.org/pool/updates/main/z/zoph/zoph_0.6-2.1etch1_all.deb       Size/MD5 checksum: 394268 147f75305b9b891fb2ab502a94be3e9e

  These files will probably be moved into the stable distribution on   its next update.

iD8DBQFHF8RmXm3vHE4uyloRAg2WAKDcWvMUaZf1ahtha4yGGnBLN2bSFwCcCKcw Z8I79ybTvjkGwBp2wveTmlA=
=Cikh
-----END PGP SIGNATURE-----

-- 
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Thu Oct 18 16:45:39 2007

This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:53:31 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library