[phpgedview] [CVE-2007-5051] cross site scripting vulnerability due to insufficient input sanitising

Bug #227288 reported by disabled.user
260
Affects Status Importance Assigned to Milestone
phpgedview (Debian)
Fix Released
Unknown
phpgedview (Ubuntu)
Won't Fix
Undecided
Unassigned
Feisty
Won't Fix
Undecided
Unassigned
Gutsy
Won't Fix
Undecided
Unassigned
Hardy
Won't Fix
Undecided
Unassigned
Intrepid
Won't Fix
Undecided
Unassigned

Bug Description

Binary package hint: phpgedview

References:
DSA-1559-1 (http://www.debian.org/security/2008/dsa-1559)

Quoting:
"It was discovered that phpGedView, an application to provide online access
to genealogical data, performed insufficient input sanitising on some
parameters, making it vulnerable to cross site scripting."

CVE References

Changed in phpgedview:
status: Unknown → Fix Released
Revision history for this message
Sarah Kowalik (hobbsee-deactivatedaccount) wrote :

Looks like we should remove this - debian already has.

[Date: Thu, 22 May 2008 19:32:29 +0000] [ftpmaster: Thomas Viehmann]
Removed the following packages from unstable:

phpgedview | 4.1.e+4.1.5-1 | source, all
phpgedview-languages | 4.1.e+4.1.5-1 | all
phpgedview-places | 4.1.e+4.1.5-1 | all
phpgedview-themes | 4.1.e+4.1.5-1 | all
Closed bugs: 458087

------------------- Reason -------------------
RoM: unmaintained, no adoptor
----------------------------------------------

Changed in phpgedview:
status: New → Triaged
Revision history for this message
Steve Kowalik (stevenk) wrote :

This has already been removed in Intrepid. Unsubscribing -archive, and Won't Fixing the Intrepid task.

Changed in phpgedview:
status: Triaged → Won't Fix
Revision history for this message
Hew (hew) wrote :

Ubuntu Feisty Fawn is no longer supported, so a SRU will not be issued for this release. Marking Feisty as Won't Fix.

Changed in phpgedview:
status: New → Won't Fix
Revision history for this message
Sergio Zanchetta (primes2h) wrote :

The 18 month support period for Gutsy Gibbon 7.10 has reached its end of life -
http://www.ubuntu.com/news/ubuntu-7.10-eol . As a result, we are closing the
Gutsy task.

Changed in phpgedview (Ubuntu Gutsy):
status: New → Won't Fix
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug and helping to make Ubuntu better. The package referred to in this bug is in universe or multiverse and reported against a release of Ubuntu (hardy) which no longer receives updates outside of the explicitly supported LTS packages. While the bug against hardy is being marked "Won't Fix" for now, if you are interested feel free to post a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures'

Please feel free to report any other bugs you may find.

Changed in phpgedview (Ubuntu Hardy):
status: New → Won't Fix
Changed in phpgedview (Ubuntu):
status: Triaged → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.