oss-sec mailing list archives
CVE request: egroupware
From: Hanno Böck <hanno () hboeck de>
Date: Wed, 30 Apr 2008 00:46:46 +0200
http://www.egroupware.org/ eGroupWare 1.4.004 FCKeditor update & security release Eingetragen von Ralf Becker am 2008/04/15 - 17:46 UPDATE: the first 1.4.004 packages contained two bugs: - felamimail gave an error "no egw_simple toolbar set" - the spellchecker / aspell did not work (it need to be configured and enabled in Admin >> Site configuration) The 1.4.004-2 tar.bz2, tar.gz and zip packages and the 1.4.005-15 rpm packages are fixing the above errors. ==> WE RECOMMEND EVERYONE UPDATES AS SOON AS POSSIBLE! The update includes all previous 1.4 updates and requires no schema update (if you upgrade within the 1.4 release). The fixed security problems are grave, if you have directories writable by the webserver in you docroot (in most windows server the complete docroot writable by default, but many linux servers are also set up that way). -- Hanno Böck Blog: http://www.hboeck.de/ GPG: 3DBD3B20 Jabber/Mail: hanno () hboeck de
Attachment:
signature.asc
Description: This is a digitally signed message part.
Current thread:
- CVE request: egroupware Hanno Böck (Apr 29)
- Re: CVE request: egroupware Steven M. Christey (Apr 30)