EGroupware SECURITY and bugfix release 1.8.007

classic Classic list List threaded Threaded
1 message Options
Ralf Becker Stylite AG Ralf Becker Stylite AG
Reply | Threaded
Open this post in threaded view

EGroupware SECURITY and bugfix release 1.8.007

This release contains security fixes for:

a) remote command execution (with rights of webserver user) for logged
in users with administrative privileges
b) cross site request forgery allowing to create new admin users or run
above commands

It is recommended to update ASAP!

Thanks to High-Tech Bridge Security Research Lab for discovering and
reporting above problems to us. See their advisory:

Please see change-log for other fixes contained in this release:

Thanks to everyone who helped with this release.

Problems are also fixed for EPL-11.1 (from 11.1.20140505 on) and current
14.1 beta (thought parts were already fixed with admin rewrite).

Please participate in 14.1 beta to ensure your instance will update
painless, when 14.1 got finally released.

Ralf Becker
Director Software Development

Stylite AG

Morschheimer Strasse 15 | Tel. +49 6352 70629 0
D-67292 Kirchheimbolanden | Fax. +49 6352 70629 30

Email: [hidden email] |

Managing Directors: Andre Keller | Ralf Becker | Gudrun Mueller
Chairman of the supervisory board: Prof. Dr. Birger Leon Kropshofer

VAT DE214280951 | Registered HRB 31158 Kaiserslautern Germany

Is your legacy SCM system holding you back? Join Perforce May 7 to find out:
• 3 signs your SCM is hindering your productivity
• Requirements for releasing software faster
• Expert tips and advice for migrating your SCM now
eGroupWare-announcement mailing list
[hidden email]

signature.asc (916 bytes) Download Attachment