DSA-4165-1 ldap-account-manager -- security update

Related Vulnerabilities: CVE-2018-8763   CVE-2018-8764  

Michal Kedzior found two vulnerabilities in LDAP Account Manager, a web front-end for LDAP directories. CVE-2018-8763 The found Reflected Cross Site Scripting (XSS) vulnerability might allow an attacker to execute JavaScript code in the browser of the victim or to redirect her to a malicious website if the victim clicks on a specially crafted link. CVE-2018-8764 The application leaks the CSRF token in the URL, which can be use by an attacker to perform a Cross-Site Request Forgery attack, in which a victim logged in LDAP Account Manager might performed unwanted actions in the front-end by clicking on a link crafted by the attacker. For the oldstable distribution (jessie), these problems have been fixed in version 4.7.1-1+deb8u1. For the stable distribution (stretch), these problems have been fixed in version 5.5-1+deb9u1. We recommend that you upgrade your ldap-account-manager packages. For the detailed security status of ldap-account-manager please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ldap-account-manager

Debian Security Advisory

DSA-4165-1 ldap-account-manager -- security update

Date Reported:
03 Apr 2018
Affected Packages:
ldap-account-manager
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-8763, CVE-2018-8764.
More information:

Michal Kedzior found two vulnerabilities in LDAP Account Manager, a web front-end for LDAP directories.

  • CVE-2018-8763

    The found Reflected Cross Site Scripting (XSS) vulnerability might allow an attacker to execute JavaScript code in the browser of the victim or to redirect her to a malicious website if the victim clicks on a specially crafted link.

  • CVE-2018-8764

    The application leaks the CSRF token in the URL, which can be use by an attacker to perform a Cross-Site Request Forgery attack, in which a victim logged in LDAP Account Manager might performed unwanted actions in the front-end by clicking on a link crafted by the attacker.

For the oldstable distribution (jessie), these problems have been fixed in version 4.7.1-1+deb8u1.

For the stable distribution (stretch), these problems have been fixed in version 5.5-1+deb9u1.

We recommend that you upgrade your ldap-account-manager packages.

For the detailed security status of ldap-account-manager please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ldap-account-manager