Advisories Blog | G5 Cyber Security

Gentoo Linux Security Advisory 200805-4

Gentoo Linux Security Advisory GLSA 200805-04 – A vulnerability has been reported in FCKEditor due to the way that file uploads are handled in the file editor/filemanager/upload/php/upload.php when a filename has multiple file extensions (CVE-2008-2041). Another vulnerability exists in the _bad_protocol_once() function in the file phpgwapi/inc/class.kses.inc.php, which allows remote attackers to bypass HTML filtering (CVE-2008-1502). Versions less than 1.4.004 are affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/66111/glsa-200805-04.txt

Source: https://packetstormsecurity.com/files/66111/Gentoo-Linux-Security-Advisory-200805-4.html

Exit mobile version