DSA-970-1 kronolith -- missing input sanitising

Related Vulnerabilities: CVE-2005-4189  

Johannes Greil of SEC Consult discovered several cross-site scripting vulnerabilities in kronolith, the Horde calendar application. The old stable distribution (woody) does not contain kronolith packages. For the stable distribution (sarge) these problems have been fixed in version 1.1.4-2sarge1. For the unstable distribution (sid) these problems have been fixed in version 2.0.6-1 of kronolith2. We recommend that you upgrade your kronolith and kronolith2 packages.

Debian Security Advisory

DSA-970-1 kronolith -- missing input sanitising

Date Reported:
14 Feb 2006
Affected Packages:
kronolith
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 342943, Bug 349261.
In Mitre's CVE dictionary: CVE-2005-4189.
More information:

Johannes Greil of SEC Consult discovered several cross-site scripting vulnerabilities in kronolith, the Horde calendar application.

The old stable distribution (woody) does not contain kronolith packages.

For the stable distribution (sarge) these problems have been fixed in version 1.1.4-2sarge1.

For the unstable distribution (sid) these problems have been fixed in version 2.0.6-1 of kronolith4.

We recommend that you upgrade your kronolith and kronolith4 packages.

Fixed in:

Debian GNU/Linux 3.1 (sarge)

Source:
http://security.debian.org/pool/updates/main/k/kronolith/kronolith_1.1.4-2sarge1.dsc
http://security.debian.org/pool/updates/main/k/kronolith/kronolith_1.1.4-2sarge1.diff.gz
http://security.debian.org/pool/updates/main/k/kronolith/kronolith_1.1.4.orig.tar.gz
Architecture-independent component:
http://security.debian.org/pool/updates/main/k/kronolith/kronolith_1.1.4-2sarge1_all.deb

MD5 checksums of the listed files are available in the original advisory.