[SECURITY] [DLA 3487-1] fusiondirectory security update and rebuild for php-cas
-------------------------------------------------------------------------
Debian LTS Advisory DLA-3487-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Abhijith PA
Tobias Frost
July 08, 2023 https://wiki.debian.org/LTS
-------------------------------------------------------------------------
Package : fusiondirectory
Version : 1.2.3-4+deb10u2
CVE ID : CVE-2022-36179 CVE-2022-36180
Debian Bug :
A potential Cross Site Scripting (XSS) vulnerablity (CVE-2022-36180) and
session handling vulnerability (CVE-2022-36179 )have been found in
fusiondirectory, a Web Based LDAP Administration Program.
Additionally, fusiondirectory has been updated to address the API change
in php-cas due to CVE-2022-39369, see DLA 3485-1 for details.
Due to this, if CAS authentication is used, fusiondirectory
will stop working until those steps are done:
- make sure to install the updated fusiondirectory-schema package for
buster.
- update the fusiondirectory core schema in LDAP by running
fusiondirectory-insert-schema -m
- switch to using the new php-cas API by running
fusiondirectory-setup --set-config-CasLibraryBool=TRUE
- set the CAS ClientServiceName to the base URL of the fusiondirectory
installation, for example:
fusiondirectory-setup --set-config-CasClientServiceName="
A fusiondirectory security update and rebuild for php-cas has been released for Debian GNU/Linux 10 LTS to address a potential Cross Site Scripting (XSS) vulnerability.