Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri, 7 Feb 2014 10:39:41 -0800
From: Galen Charlton <>
Subject: CVE request: multiple issues in Koha


As current release manager for Koha, I'd like to request CVE number(s)
for the following issues that were addressed in a security release

Release announcement:

Issues fixed with the release:

[1] tools/ could be used to read arbitrary files on the server
[2] the staff interface help editor could be used to modify or create
arbitrary files on the server
[3] could be used to write to arbitrary files on the server
[4] the MARC framework import/export function did not require
authentication, and could be used to perform unexpected SQL commands


Galen Charlton
Manager of Implementation
Equinox Software, Inc. / The Open Source Experts
direct: +1 770-709-5581
cell:   +1 404-984-4366
skype:  gmcharlt
Supporting Koha and Evergreen: &

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.