Debian Security Advisory

DSA-4165-1 ldap-account-manager -- security update

Date Reported:
03 Apr 2018
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2018-8763, CVE-2018-8764.
More information:

Michal Kedzior found two vulnerabilities in LDAP Account Manager, a web front-end for LDAP directories.

  • CVE-2018-8763

    The found Reflected Cross Site Scripting (XSS) vulnerability might allow an attacker to execute JavaScript code in the browser of the victim or to redirect her to a malicious website if the victim clicks on a specially crafted link.

  • CVE-2018-8764

    The application leaks the CSRF token in the URL, which can be use by an attacker to perform a Cross-Site Request Forgery attack, in which a victim logged in LDAP Account Manager might performed unwanted actions in the front-end by clicking on a link crafted by the attacker.

For the oldstable distribution (jessie), these problems have been fixed in version 4.7.1-1+deb8u1.

For the stable distribution (stretch), these problems have been fixed in version 5.5-1+deb9u1.

We recommend that you upgrade your ldap-account-manager packages.

For the detailed security status of ldap-account-manager please refer to its security tracker page at: