Postfixadmin: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201209-18 / postfixadmin |
| Release Date |
September 27, 2012 |
| Latest Revision |
September 27, 2012: 1 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| www-apps/postfixadmin |
<
2.3.5 |
>=
2.3.5 |
All supported architectures
|
Related bugreports:
#400971
Synopsis
Multiple vulnerabilities have been found in Postfixadmin which may
lead to SQL injection or cross-site scripting attacks.
2.
Impact Information
Background
Postfixadmin is a web-based management tool for Postfix-style virtual
domains and users.
Description
Multiple SQL injection vulnerabilities (CVE-2012-0811) and cross-site
scripting vulnerabilities (CVE-2012-0812) have been found in
Postfixadmin.
Impact
A remote attacker could exploit these vulnerabilities to execute
arbitrary SQL statements or arbitrary HTML and script code.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Postfixadmin users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/postfixadmin-2.3.5"
|
4.
References
|