CVE-2008-1475

Publication date 24 March 2008

Last updated 17 July 2025


Ubuntu priority

Description

The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.

Read the notes from the security team

Status

Package Ubuntu Release Status
roundup 7.10 gutsy
Not affected
7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected

Notes


jdstrand

per Debian, code introduced in 1.4.0


Access our resources on patching vulnerabilities