Security Vulnerability in PLA 1.1.

Deon George <[email protected]>
Newsgroups gmane.comp.ldap.phpldapadmin.user,gmane.comp.ldap.davedap
Message-ID <[email protected]>
Folks,

A vulnerability has been reported in PLA 1.1.0.5, and probably affects
all PLA 1.1 versions. Details of the vulnerability are here:

http://www.exploit-db.com/exploits/10410
http://secunia.com/advisories/37848/

I'm not able to reproduce it on PLA 1.2, however, if somebody can,
please let me know how and I'll release a fix as soon as I find out.

I have just made some additional sanity checking in PLA 1.2 anyway and
will release that as 1.2.0.5 soon (but I'll wait to hear any other info
on the current vulnerability, just in case I've overlooked something).

...deon


------------------------------------------------------------------------------
This SF.Net email is sponsored by the Verizon Developer Community
Take advantage of Verizon's best-in-class app development support
A streamlined, 14 day to market process makes app distribution fast and easy
Join now and get one step closer to millions of Verizon customers
http://p.sf.net/sfu/verizon-dev2dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.