Oval Definition:oval:org.mitre.oval:def:8203
Revision Date:2014-06-23Version:18
Title:DSA-1580 phpgedview -- programming error
Description:It was discovered that phpGedView, an application to provide online access to genealogical data, allowed remote attackers to gain administrator privileges due to a programming error. Note: this problem was a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems. Resolving this problem was only possible by completely reworking the API, which is not considered appropriate for a security update. Since these are peripheral functions probably not used by the large majority of package users, it was decided to remove these interfaces. If you require that interface nonetheless, you are advised to use a version of phpGedView backported from Debian Lenny, which has a completely redesigned API.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-2064
DSA-1580
Platform(s):Debian GNU/Linux 4.0
Product(s):phpgedview
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Installed architecture is all
  • AND Packages section
  • phpgedview-places is earlier than 4.0.2.dfsg-4
  • OR phpgedview-themes is earlier than 4.0.2.dfsg-4
  • OR phpgedview is earlier than 4.0.2.dfsg-4
  • OR phpgedview-languages is earlier than 4.0.2.dfsg-4
  • BACK