Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2011-4075

Published: 2 November 2011

The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.

Priority

Medium

Status

Package Release Status
phpldapadmin
Launchpad, Ubuntu, Debian
hardy Ignored
(end of life)
lucid
Released (1.2.0.5-1ubuntu1.10.04.2)
maverick
Released (1.2.0.5-1.1ubuntu1.1)
natty
Released (1.2.0.5-2ubuntu1.11.04.1)
oneiric
Released (1.2.0.5-2ubuntu1.11.10.1)
upstream
Released (1.2.0.5-2.1)
Patches:
upstream: http://phpldapadmin.git.sourceforge.net/git/gitweb.cgi?p=phpldapadmin/phpldapadmin;a=commit;h=76e6dad13ef77c5448b8dfed1a61e4acc7241165
vendor: http://www.debian.org/security/2011/dsa-2333