[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1580 phpgedview -- programming error

ID: oval:org.mitre.oval:def:8203Date: (C)2009-12-15   (M)2021-07-09
Class: PATCHFamily: unix




It was discovered that phpGedView, an application to provide online access to genealogical data, allowed remote attackers to gain administrator privileges due to a programming error. Note: this problem was a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems. Resolving this problem was only possible by completely reworking the API, which is not considered appropriate for a security update. Since these are peripheral functions probably not used by the large majority of package users, it was decided to remove these interfaces. If you require that interface nonetheless, you are advised to use a version of phpGedView backported from Debian Lenny, which has a completely redesigned API.

Platform:
Debian 4.0
Product:
phpgedview
Reference:
DSA-1580
CVE-2008-2064
CVE    1
CVE-2008-2064
CPE    1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies