Bug 934346 (CVE-2015-3923) - VUL-1: CVE-2015-3923: coppermine: directory enumeration vulnerability
Summary: VUL-1: CVE-2015-3923: coppermine: directory enumeration vulnerability
Status: RESOLVED FIXED
Alias: CVE-2015-3923
Product: openSUSE.org
Classification: openSUSE
Component: 3rd party software (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal (vote)
Target Milestone: ---
Assignee: Andreas Stieger
QA Contact: E-mail List
URL: https://smash.suse.de/issue/117556/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-06-11 10:09 UTC by Andreas Stieger
Modified: 2015-06-16 13:11 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-06-11 10:09:08 UTC
Coppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate
directories via a full path in the folder parameter to minibrowser.php.

This is a courtesy bug for server:php:applications/coppermine. Not in the distribution.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3923
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3923
Comment 1 Swamp Workflow Management 2015-06-11 22:00:14 UTC
bugbot adjusting priority
Comment 2 Joop Boonen 2015-06-16 13:01:08 UTC
Build new package with request: #312223
Comment 3 Joop Boonen 2015-06-16 13:05:21 UTC
This version has been accepted by myself:
https://build.opensuse.org/package/show/server:php:applications/coppermine
Comment 4 Andreas Stieger 2015-06-16 13:11:40 UTC
nothing else to be done