Secunia Logo
Netsikker nu! 2008
 
Debian update for phpbb2
Secunia Advisory: SA28871
Release Date: 2008-02-11
Popularity: 4,506 views

Critical:
Less critical
Impact: Cross Site Scripting
Manipulation of data
System access
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.1
Debian GNU/Linux 4.0
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-4758
CVE-2006-6839
CVE-2006-6840
CVE-2006-6508
CVE-2006-6841
CVE-2008-0471


Description:
Debian has issued an update for phpbb2. This fixes some vulnerabilities, which can be exploited by malicious users to compromise a vulnerable system and by malicious people to conduct cross-site scripting and cross-site request forgery attacks.

For more information:
SA22188
SA23283
SA28630

Solution:
Apply updated packages.

-- Debian GNU/Linux 3.1 alias sarge --

Source archives:

http://security.debian.org/pool/updat...hpbb2/phpbb2_2.0.13+1-6sarge4.diff.gz
Size/MD5 checksum: 67912 c403597d08f4c5af0f62b84c5ee72a7e
http://security.debian.org/pool/updat.../p/phpbb2/phpbb2_2.0.13+1.orig.tar.gz
Size/MD5 checksum: 3340445 678d0cb0372e46402a472c510fb90d78
http://security.debian.org/pool/updat.../p/phpbb2/phpbb2_2.0.13+1-6sarge4.dsc
Size/MD5 checksum: 1011 d5ca94a7a4c2b3468428a993a1dbc5cc

Architecture independent packages:

http://security.debian.org/pool/updat...bb2-conf-mysql_2.0.13-6sarge4_all.deb
Size/MD5 checksum: 37766 f0df2114bd60d9b84fbda1d241294fdd
http://security.debian.org/pool/updat.../phpbb2/phpbb2_2.0.13-6sarge4_all.deb
Size/MD5 checksum: 526154 944e55e056fc34d970e95b78201589fe
http://security.debian.org/pool/updat...pbb2-languages_2.0.13-6sarge4_all.deb
Size/MD5 checksum: 2868920 f10c4962035ede6e02417b8098efeda0

-- Debian GNU/Linux 4.0 alias etch --

Source archives:

http://security.debian.org/pool/updates/main/p/phpbb2/phpbb2_2.0.21-7.dsc
Size/MD5 checksum: 1051 88ad3a4f2ee714cce779873b53ebd323
http://security.debian.org/pool/updates/main/p/phpbb2/phpbb2_2.0.21.orig.tar.gz
Size/MD5 checksum: 3203456 30383a9bf6c5d21736e4bdf9ec7852d5
http://security.debian.org/pool/updates/main/p/phpbb2/phpbb2_2.0.21-7.diff.gz
Size/MD5 checksum: 90580 896f80500e90867741c516e57fc8bfcc

Architecture independent packages:

http://security.debian.org/pool/updat...bb2/phpbb2-languages_2.0.21-7_all.deb
Size/MD5 checksum: 2791410 afd8a0fe8138c8a5cf00a3e4ac10ac59
http://security.debian.org/pool/updates/main/p/phpbb2/phpbb2_2.0.21-7_all.deb
Size/MD5 checksum: 554842 e8825ef3431bfe7ccf72f9f59f13a119
http://security.debian.org/pool/updat...b2/phpbb2-conf-mysql_2.0.21-7_all.deb
Size/MD5 checksum: 53706 49baf96bcc1c273a93e8bb5169dca722

-- Debian GNU/Linux unstable alias sid --

Fixed in version 2.0.22-3.

Original Advisory:
http://lists.debian.org/debian-securi...-security-announce-2008/msg00048.html

Other References:
SA22188:
http://secunia.com/advisories/22188/

SA23283:
http://secunia.com/advisories/23283/

SA28630:
http://secunia.com/advisories/28630/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

7th Oct, 2008
New advisories: 19
New vulnerabilities: 68
Updated advisories: 62

Moderately // 306 views
Debian update for php5
Moderately // 234 views
Atarone CMS Multiple Vulnerabilities
Moderately // 264 views
Debian update for squid
Less // 269 views
SUSE update for mercurial
Moderately // 311 views
SUSE update for openssh
Less // 246 views
Fedora update for mediawiki

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Juniper Products Neighbor Discovery Protocol Neighbor Solicitation Vulnerability // 32 views
2. Debian update for php5 // 29 views
3. Debian update for squid // 29 views
4. Atarone CMS Multiple Vulnerabilities // 28 views
5. SUSE update for openssh // 28 views
6. SUSE update for mercurial // 27 views
7. MetaGauge Directory Traversal Vulnerability // 26 views
8. H-Sphere webshell4 Cross-Site Scripting and Request Forgery // 24 views
9. CMME Information Disclosure Security Issues // 23 views
10. Fedora update for mediawiki // 23 views