Debian Security Advisory

DSA-766-1 webcalendar -- authorisation failure

Date Reported:
26 Jul 2005
Affected Packages:
webcalendar
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 315671.
In the Bugtraq database (at SecurityFocus): BugTraq ID 14072.
In Mitre's CVE dictionary: CVE-2005-2320.
More information:

A vulnerability has been discovered in webcalendar, a PHP based multi-user calendar, that can lead to the disclosure of sensitive information to unauthorised parties.

The old stable distribution (woody) does not contain the webcalendar package.

For the stable distribution (sarge) this problem has been fixed in version 0.9.45-4sarge1.

For the unstable distribution (sid) this problem has been fixed in version 0.9.45-6.

We recommend that you upgrade your webcalendar package.

Fixed in:

Debian GNU/Linux 3.1 (sarge)

Source:
http://security.debian.org/pool/updates/main/w/webcalendar/webcalendar_0.9.45-4sarge1.dsc
http://security.debian.org/pool/updates/main/w/webcalendar/webcalendar_0.9.45-4sarge1.diff.gz
http://security.debian.org/pool/updates/main/w/webcalendar/webcalendar_0.9.45.orig.tar.gz
Architecture-independent component:
http://security.debian.org/pool/updates/main/w/webcalendar/webcalendar_0.9.45-4sarge1_all.deb

MD5 checksums of the listed files are available in the original advisory.