Bug 110350 - [PATCH] (security?) upgrade of sql-ledger
Summary: [PATCH] (security?) upgrade of sql-ledger
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Lars Thegler
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-03-15 19:40 UTC by anarcat+register
Modified: 2007-03-16 12:00 UTC (History)
0 users

See Also:


Attachments
file.diff (1.12 KB, patch)
2007-03-15 19:40 UTC, anarcat+register
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description anarcat+register 2007-03-15 19:40:06 UTC
The current version of SQL_Ledger in the ports system is vulnerable to a "authentication bypass vulnerability allowing full access to the administrator interface of LedgerSMB 1.1 and SQL-Ledger 2.x." 2.6.26 was released to correct this problem.

http://www.securityfocus.com/archive/1/462375

How-To-Repeat: 
N/A
Comment 1 Edwin Groothuis freebsd_committer freebsd_triage 2007-03-16 07:22:15 UTC
Responsible Changed
From-To: freebsd-ports-bugs->lth

Over to maintainer
Comment 2 dfilter service freebsd_committer freebsd_triage 2007-03-16 11:48:41 UTC
lth         2007-03-16 11:48:32 UTC

  FreeBSD ports repository

  Modified files:
    security/vuxml       vuln.xml 
  Log:
  Document sql-ledger vulnerability
  
  PR:             ports/110350
  Submitted by:   Antoine Beaupre <anarcat@koumbit.org>
  
  Revision  Changes    Path
  1.1299    +42 -1     ports/security/vuxml/vuln.xml
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 3 dfilter service freebsd_committer freebsd_triage 2007-03-16 11:57:19 UTC
lth         2007-03-16 11:57:15 UTC

  FreeBSD ports repository

  Modified files:
    finance/sql-ledger   Makefile distinfo pkg-plist 
  Log:
  Update to 2.6.26, fixing authentication bypass vulnerability
  
  For changes, see:
  
    http://www.sql-ledger.org/cgi-bin/nav.pl?page=news.html&title=What's%20New
  
  PR:             ports/110350
  Submitted by:   Antoine Beaupre <anarcat@koumbit.org>
  Security:       http://www.vuxml.org/freebsd/8e02441d-d39c-11db-a6da-0003476f14d3.html
  
  Revision  Changes    Path
  1.16      +1 -1      ports/finance/sql-ledger/Makefile
  1.15      +3 -3      ports/finance/sql-ledger/distinfo
  1.13      +1 -1      ports/finance/sql-ledger/pkg-plist
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 4 Lars Thegler freebsd_committer freebsd_triage 2007-03-16 11:57:49 UTC
State Changed
From-To: open->closed

Committed. Thanks!