TITLE: Debian update for phpgroupware SECUNIA ADVISORY ID: SA17616 VERIFY ADVISORY: http://secunia.com/advisories/17616/ CRITICAL: Moderately critical IMPACT: Cross Site Scripting, Manipulation of data, Exposure of system information, Exposure of sensitive information WHERE: >From remote OPERATING SYSTEM: Debian GNU/Linux 3.0 http://secunia.com/product/143/ Debian GNU/Linux 3.1 http://secunia.com/product/5307/ Debian GNU/Linux unstable alias sid http://secunia.com/product/530/ DESCRIPTION: Debian has issued an update for phpgroupware. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and manipulate certain information. For more information: SA17570 SOLUTION: Apply updated packages. -- Debian GNU/Linux 3.0 alias woody -- Source archives: http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware_0.9.14-0.RC3.2.woody5.dsc Size/MD5 checksum: 1648 b566e2f51056fa8ac7d8b251d7a96ff9 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware_0.9.14-0.RC3.2.woody5.diff.gz Size/MD5 checksum: 450241 6eeab6967838532bd4ff397e3594de18 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware_0.9.14.orig.tar.gz Size/MD5 checksum: 8356188 22e715d0884d09aa848d694701a85b6b Architecture independent components: http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-addressbook_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 79298 c2b985d562329e5dadaa007053b13b0d http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-admin_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 142622 c5773f488d74e817e3dd017f7d63f396 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-api-doc_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 283750 026bc3f52bdf4cfb9e89396b1d658f05 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-api_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 2110096 d07c843fe0dc2f56c908ab62a7c3932f http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-bookkeeping_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 40660 95ba9a9bc2a615a0f4fbec5de1af138d http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-bookmarks_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 121642 aa2250a0f423b29960a859ceca8f536a http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-brewer_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 63996 a5adeb85c78d0b0d934a4c3d89533120 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-calendar_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 224328 8ff4ae362e2943bf5723f3b452e38874 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-chat_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 19520 a0ad48a10a9ef92b21385dac1647951c http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-chora_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 60344 5c914d9839df514a7797b66e03abcb34 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-comic_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 326802 f6dbeb5cfd3f1e8fcd30577d74e0c3a3 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-core-doc_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 89716 46184743bb37272b7575fefe07769e5f http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-core_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 19506 9bee51413e1d2e7e233d72320d974648 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-developer-tools_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 41384 c7b071fd0896d64c90c85f034ead73ec http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-dj_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 45948 5d7b9021bbe8645e376b652e321a2864 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-eldaptir_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 47580 274aa69642d97f7eae830e5a2f8853a5 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-email_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 313796 a8fcc446290f7ca6d8770a5cf6d133b5 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-filemanager_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 37968 a339be1b0b48c3f25d0c13685ec32c94 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-forum_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 48320 d580900a62cfc91c6ed00c28dac23de3 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-ftp_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 39984 8c59ea1ecf380674e2af66120b3fcb72 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-headlines_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 59948 76b9143103e8f3496dd9ad58790039f8 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-hr_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 24306 ba9f2259950afb73c3617e52945f933f http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-img_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 39250 72811641f7f714455dc8216ae3ad470f http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-infolog_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 93448 44146630a16580e20eb511ddb710d9ac http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-inv_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 89894 e3c507eeffe88fb1e0dfccb3678a81f7 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-manual_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 93100 f87c371b8b37455f5d3766d65e081cbe http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-messenger_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 30260 9294cbfad065ca30240a25cca10ab1c5 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-napster_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 26678 07d0ae30f508575cd66b820b7be8d617 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-news-admin_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 32100 77281a49f092426a3d68d55d0df67256 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-nntp_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 45032 7ff68e4368db0ae58a26dccc6095f762 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-notes_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 27724 415876cf611fb4d676785923b3dd4d7b http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-phonelog_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 22260 71f59501cb31e2ac155dda3533f8d8a0 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-phpsysinfo_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 35596 0432bcee4145c34c13b83c1a097b04cc http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-phpwebhosting_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 62238 12c217f1885578d005eeb778ae874048 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-polls_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 30190 41f6d69d69ebd5d1cf13c61cc8795790 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-preferences_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 46148 de949dd6cd41c6817c40af466d5b2ea2 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-projects_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 86830 d3228f43e0c7e93cb249e7aa06707985 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-registration_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 36458 a81bab670414b8f322b0700694deca6e http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-setup_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 273064 fb1749a7609c2d858388f01c421e4950 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-skel_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 31440 a88512cf06f4bac46cf0ad8a6f2ed046 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-soap_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 23096 d7b9db3f1fe52ccb69a91db466ada9da http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-stocks_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 27168 30abd675055b16e1867fc47b7f9f0f03 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-todo_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 43666 f395710610352fa8bb0992473e03e84e http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-tts_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 46672 39d14cff54c5dc978d87d77705f6fa64 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-wap_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 28112 76da6ba398ed66d7819e2bb54a1a5dc5 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-weather_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 498832 92956b14cbe894dce47ca3a792399258 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-xmlrpc_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 74958 dd01b3381e6de01f5f484bd3a4e116fe http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware_0.9.14-0.RC3.2.woody5_all.deb Size/MD5 checksum: 26246 d5e2072c9d0ee92112b45aadf393b002 -- Debian GNU/Linux 3.1 alias sarge -- Source archives: http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware_0.9.16.005-3.sarge4.dsc Size/MD5 checksum: 1613 a7a22d0059c9e0fbe9dc6a180dda1861 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware_0.9.16.005-3.sarge4.diff.gz Size/MD5 checksum: 36821 24b9ee58c7351e5ad759004f3de64850 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware_0.9.16.005.orig.tar.gz Size/MD5 checksum: 19442629 5edd5518e8f77174c12844f9cfad6ac4 Architecture independent components: http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-addressbook_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 176708 22ff5daa5c3da9c4359458958c4a8210 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-admin_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 186486 61ff479a17df309769400555758b4be4 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-bookmarks_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 101110 0f5158dbadf4074335dae1dac8d9322c http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-calendar_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 324210 0b831eb86b630d98548a32ef86e9742e http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-chat_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 23338 b5cbabc134dc0bdd7584d05e8cf1ca93 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-comic_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 434332 9255e255e3737fe45f7358301a8354f5 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-core_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 6630 80771055932dada464c017bd8ec937ef http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-developer-tools_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 33450 19b7940ea349f48bcc76db69a4177888 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-dj_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 42902 5f25541a98e5837d5ed0f580449436e3 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-eldaptir_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 50592 a810c608dca20a544adce8957294ad6e http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-email_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 1118084 13f46335c0dbbb4909d31862a3a92aac http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-etemplate_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 1329600 fe31f9dd77a2c463eb71aff88f5984e6 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-felamimail_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 180306 516269d09dbfa8a503cf8899179815f9 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-filemanager_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 91738 8079e7b3f16ac9d269da155a77176d8b http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-folders_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 166508 4fe6e827ca8a0a64147d893ef43ae17d http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-forum_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 45692 52ec682c7169801d202dc0afcc7b9f1f http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-ftp_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 36540 2ab8e0f4bc0cc176153cec4b0ef8bbb8 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-fudforum_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 1355886 87aca5504ca5aeac4219e7731371a510 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-headlines_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 64042 df3b3d21b61791d4cf3e1eee415c25dc http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-hr_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 18964 3b4387bf2556061ecdb1456ae3925ac8 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-img_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 8716 c539c846f5547756b8aa53f6cba1c4a3 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-infolog_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 136528 2a2557b6feabe846ddff1a301d7875de http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-manual_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 90760 674ab476f67efe8badd90ece9a8a0f61 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-messenger_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 26118 aa5d5a23f20c79c14bc9a6849370ff14 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-news-admin_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 41436 003c97150c1da9f3812521f2277ec433 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-nntp_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 47062 505cbe3eaabc0838e33445ba313ab0f5 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-notes_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 35086 c5e785e89763701bb63782b061c2089b http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-phonelog_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 20822 88ef1cba9d2f8d3814d95e4b18c7c3ea http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-phpbrain_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 40298 04c2444dd4ebc34a70541eaad89e477c http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-phpgwapi_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 9678082 4176bb65f06984af183ea98f38ddb628 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-phpsysinfo_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 116710 b500b5681e3ad9c7fb9e58ee6355815b http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-polls_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 31650 a69d663710889a65c5e00445da2bb15f http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-preferences_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 59750 74e816593527a8db61e6ade7696fe6d7 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-projects_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 120450 e812184d80be8ce7e4a5d52582ef268b http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-qmailldap_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 23616 2d0a6db5dc08631a4149366294c25036 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-registration_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 30070 f4220aec25d9dc4f857c93e29d9b8585 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-setup_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 267402 2cd8c3e2bd2ebcdb1f47cb7fb69419f7 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-sitemgr_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 902722 906af3e7dc66fe42d796e4317c238781 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-skel_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 19312 41653329553a614b6d073583f28df0c4 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-soap_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 24152 a900899343d5a0f95490eda6c6798cce http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-stocks_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 22094 711877afe59a6dd5c3cf500ff40f0285 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-todo_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 50388 979958e0910ab1428b88d6146be42d7f http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-tts_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 55902 3932ef425f1f9959a8943d2e6457f54c http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-wiki_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 70444 544f88a951610a6b673371f0963cba21 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware-xmlrpc_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 63086 7c95449de2e66de06b3f4c763e9de168 http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupware_0.9.16.005-3.sarge4_all.deb Size/MD5 checksum: 156300 4eb60f3560ba1a52265edab63c6f8f2b -- Debian GNU/Linux unstable alias sid -- Fixed in version 0.9.16.008-2. ORIGINAL ADVISORY: http://www.debian.org/security/2005/dsa-898 OTHER REFERENCES: SA17570: http://secunia.com/advisories/17570/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------