-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 _______________________________________________________________________ Mandriva Linux Security Advisory MDVSA-2012:020 http://www.mandriva.com/security/ _______________________________________________________________________ Package : phpldapadmin Date : February 15, 2012 Affected: Enterprise Server 5.0 _______________________________________________________________________ Problem Description: A vulnerability has been found and corrected in phpldapadmin: Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php (CVE-2012-0834). The updated packages have been patched to correct this issue. _______________________________________________________________________ References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0834 _______________________________________________________________________ Updated Packages: Mandriva Enterprise Server 5: b4099f71ab2b3ac8052b23f6c6ad8551 mes5/i586/phpldapadmin-1.2.2-0.3mdvmes5.2.noarch.rpm 61cf472322320166cdcfcf80df160402 mes5/SRPMS/phpldapadmin-1.2.2-0.3mdvmes5.2.src.rpm Mandriva Enterprise Server 5/X86_64: e6431121604ed1e8409853c75c40f51b mes5/x86_64/phpldapadmin-1.2.2-0.3mdvmes5.2.noarch.rpm 61cf472322320166cdcfcf80df160402 mes5/SRPMS/phpldapadmin-1.2.2-0.3mdvmes5.2.src.rpm _______________________________________________________________________ To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing: gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98 You can view other update advisories for Mandriva Linux at: http://www.mandriva.com/security/advisories If you want to report vulnerabilities, please contact security_(at)_mandriva.com _______________________________________________________________________ Type Bits/KeyID Date User ID pub 1024D/22458A98 2000-07-10 Mandriva Security Team <security*mandriva.com> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iD8DBQFPO2kymqjQ0CJFipgRAnRKAKC+2dSCDxfcK6bFE9iDYhz8vo3AGwCgmmby TWGsb/tKfaYKjmr/60eiWl8= =mytH -----END PGP SIGNATURE-----