Debian Security Advisory
DSA-970-1 kronolith -- missing input sanitising
- Date Reported:
- 14 Feb 2006
- Affected Packages:
- kronolith
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 342943, Bug 349261.
In Mitre's CVE dictionary: CVE-2005-4189. - More information:
-
Johannes Greil of SEC Consult discovered several cross-site scripting vulnerabilities in kronolith, the Horde calendar application.
The old stable distribution (woody) does not contain kronolith packages.
For the stable distribution (sarge) these problems have been fixed in version 1.1.4-2sarge1.
For the unstable distribution (sid) these problems have been fixed in version 2.0.6-1 of kronolith2.
We recommend that you upgrade your kronolith and kronolith2 packages.
- Fixed in:
-
Debian GNU/Linux 3.1 (sarge)
- Source:
- http://security.debian.org/pool/updates/main/k/kronolith/kronolith_1.1.4-2sarge1.dsc
- http://security.debian.org/pool/updates/main/k/kronolith/kronolith_1.1.4-2sarge1.diff.gz
- http://security.debian.org/pool/updates/main/k/kronolith/kronolith_1.1.4.orig.tar.gz
- http://security.debian.org/pool/updates/main/k/kronolith/kronolith_1.1.4-2sarge1.diff.gz
- Architecture-independent component:
- http://security.debian.org/pool/updates/main/k/kronolith/kronolith_1.1.4-2sarge1_all.deb
MD5 checksums of the listed files are available in the original advisory.