Vulnerability Solutions

The WatchMouse Periodic Vulnerability Scan checks for the vulnerability below. To see the most recently added vulnerability solutions that are scanned by WatchMouse, go to the Vulnerability Solutions overview

Category: Debian Local Security Checks Risk factor: High Added: 16 Mar 2010
Synopsis:

The remote host is missing the DSA-2013 security update

Description:

Nahuel Grisolia discovered two vulnerabilities in Egroupware, a web-based groupware suite: Missing input sanitising in the spellchecker integration may lead to the execution of arbitrary commands and a cross-site scripting vulnerability was discovered in the login page. For the stable distribution (lenny), these problems have been fixed in version 1.4.004-2.dfsg-4.2.
The upcoming stable distribution (squeeze), no longer contains egroupware
packages.

See also:

http://www.debian.org/security/2010/dsa-2013

Solution:

The Debian project recommends that you upgrade your egroupware packages.

Risk factor:

High