Package: egroupware-fudforum
Severity: grave
Tags: security
Justification: user security hole

egroupware embeds a shared/forked copy of "fudforum", which was
vulnerable to:

| The Avatar upload feature in FUD Forum before 2.7.0 does not properly
| verify uploaded files, which allows remote attackers to execute arbitrary
| PHP code via a file with a .php extension that contains image data
| followed by PHP code.

(Please see http://secunia.com/advisories/16627/ for details)

The vulnerable code is also in egroupware-fudforum. See
http://www.mail-archive.com/phpgroupware-cvs@gnu.org/msg21210.html for a
fix.

Cheers,
Stefan


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to