CVE-2008-5968

Publication date 26 January 2009

Last updated 24 July 2024


Ubuntu priority

Description

Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cookie_language parameter in a phpicalendar_* cookie, a different vector than CVE-2006-1292.

Status

Package Ubuntu Release Status
phpicalendar 10.10 maverick Not in release
10.04 LTS lucid Not in release
9.10 karmic Not in release
9.04 jaunty Ignored end of life
8.10 intrepid Ignored end of life, was needed
8.04 LTS hardy Not in release
7.10 gutsy Not in release
6.06 LTS dapper Not in release