SECURITY: Horde_Auth 1.0.4

Jan Schneider <[email protected]>
Newsgroups gmane.comp.horde.announce
Message-ID <20110608164921.Horde.Zb__dhPcj3hN74vxaldhq3A__37085.4197456085$1307544608$gmane$org@neo.wg.de>
The Horde Team has released version 1.0.4 of the Horde_Auth framework package.

This is an important security release that fixes a serious bug in the  
composite authentication driver that could allow a user to access the  
Horde system even though authentication failed for a sub-driver.

Affected are all versions of the Horde_Auth library from 1.0.0alpha1  
to 1.0.3. Only systems using the composite authentication driver are  
affected. Horde applications that require another login step, e.g.  
IMP, are not affected, even if this 2nd authentication is done  
transparently.

All affected systems should update the Horde_Auth package IMMEDIATELY.  
This can be done using the PEAR installer:

    pear upgrade horde/horde_auth

The Horde Team.


-- 
Horde announcements mailing list
You are subscribed to this list as: [email protected]
To unsubscribe, mail: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.