Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Order Openwall GNU/*/Linux 2.0 on a CD with delivery worldwide
[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Wed, 30 Apr 2008 00:46:46 +0200
From: Hanno Böck <hanno@...eck.de>
To: oss-security@...ts.openwall.com
Subject: CVE request: egroupware

http://www.egroupware.org/

eGroupWare 1.4.004 FCKeditor update & security release
Eingetragen von Ralf Becker am 2008/04/15 - 17:46

UPDATE: the first 1.4.004 packages contained two bugs:
- felamimail gave an error "no egw_simple toolbar set"
- the spellchecker / aspell did not work (it need to be configured and enabled 
in Admin >> Site configuration)

The 1.4.004-2 tar.bz2, tar.gz and zip packages and the 1.4.005-15 rpm packages 
are fixing the above errors.

==> WE RECOMMEND EVERYONE UPDATES AS SOON AS POSSIBLE!

The update includes all previous 1.4 updates and requires no schema update (if 
you upgrade within the 1.4 release).

The fixed security problems are grave, if you have directories writable by the 
webserver in you docroot (in most windows server the complete docroot 
writable by default, but many linux servers are also set up that way). 


-- 
Hanno Böck		Blog:		http://www.hboeck.de/
GPG: 3DBD3B20		Jabber/Mail:	hanno@...eck.de

[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux