phpsysinfo / phpsysinfo

phpSysInfo: a customizable PHP script that displays information about your system nicely
http://phpsysinfo.github.io/phpsysinfo
GNU General Public License v2.0
1.38k stars 233 forks source link

About CVE-2006-3360 #368

Closed williamdes closed 1 year ago

williamdes commented 1 year ago

Did you known about CVE-2006-3360?

It's still marked unfixed on the security tracker, what version did fix it?

https://security-tracker.debian.org/tracker/source-package/phpsysinfo

williamdes commented 1 year ago

/cc @carnil

So it was normally fixed with https://tracker.debian.org/news/815821/accepted-phpsysinfo-325-3-source-into-unstable/

namiltd commented 1 year ago

Finally fixed in phpSysInfo v3.2.5 (https://github.com/phpsysinfo/phpsysinfo/commit/60b5bbb5d1cc17f44050e99a3e746f55a4fd4e18)

williamdes commented 1 year ago

Thank you for the reference and help, it will be updated on the Debian tracker

williamdes commented 1 year ago

I submitted https://github.com/github/advisory-database/pull/1611 And asked the CVE MITRE team to update the CVE to add the new informations

carnil commented 1 year ago

/cc @carnil

So it was normally fixed with https://tracker.debian.org/news/815821/accepted-phpsysinfo-325-3-source-into-unstable/

Thanks, updated tracker information https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db60257af5ba6985bdc6b9fcbbfd8c9993b01542

williamdes commented 1 year ago

I submitted github/advisory-database#1611 And asked the CVE MITRE team to update the CVE to add the new informations

Got updated https://www.cve.org/CVERecord?id=CVE-2006-3360