|
From: | Sigurd Nes |
Subject: | Re: [Phpgroupware-developers] PHPGW - SECURITY WARNING ALL BRANCHES |
Date: | Thu, 03 Jul 2003 11:55:43 +0200 |
User-agent: | Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4b) Gecko/20030525 Thunderbird/0.1a |
Dave Hall wrote:
Hi all, Please be aware there is minor security advisory for phpgw. See http://www.security-corporation.com/articles-20030702-005.html for more info. There is also a vfs security patch also. This prevents the vfs path being in the document root, which has been exploited in other php based groupware suites. We have fixed this in cvs for all branches (14, 16preRC and HEAD). This affects all previous versions of phpgroupare. We will be releasing packaged releases in about 12hours.
Can't see it commited to HEAD :-( Sigurd
[Prev in Thread] | Current Thread | [Next in Thread] |