First published: Mon Apr 11 2016(Updated: )
The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache LDAP Studio | =0.6.0 | |
Apache LDAP Studio | =0.7.0 | |
Apache LDAP Studio | =0.8.0 | |
Apache LDAP Studio | =0.8.1 | |
Apache Directory Studio | =1.0.0 | |
Apache Directory Studio | =1.0.1 | |
Apache Directory Studio | =1.1.0 | |
Apache Directory Studio | =1.1.0-rc1 | |
Apache Directory Studio | =1.1.0-rc2 | |
Apache Directory Studio | =1.2.0 | |
Apache Directory Studio | =1.2.0-rc1 | |
Apache Directory Studio | =1.3.0 | |
Apache Directory Studio | =1.3.0-rc1 | |
Apache Directory Studio | =1.4.0 | |
Apache Directory Studio | =1.5.0 | |
Apache Directory Studio | =1.5.1 | |
Apache Directory Studio | =1.5.2 | |
Apache Directory Studio | =1.5.3 | |
Apache Directory Studio | =2.0.0-milestone1 | |
Apache Directory Studio | =2.0.0-milestone2 | |
Apache Directory Studio | =2.0.0-milestone3 | |
Apache Directory Studio | =2.0.0-milestone4 | |
Apache Directory Studio | =2.0.0-milestone5 | |
Apache Directory Studio | =2.0.0-milestone6 | |
Apache Directory Studio | =2.0.0-milestone7 | |
Apache Directory Studio | =2.0.0-milestone8 | |
Apache Directory Studio | =2.0.0-milestone9 | |
maven/org.apache.directory.studio:org.apache.directory.studio.ldapbrowser.core | <2.0.0.v20151221-M10 | 2.0.0.v20151221-M10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.