========================================================================== Ubuntu Security Notice USN-4620-1 November 05, 2020 phpldapadmin vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: phpLDAPadmin could be made to crash if it received specially crafted input. Software Description: - phpldapadmin: A web-based LDAP client Details: It was discovered that phpLDAPadmin didn't properly sanitize before being echoed to the user. A remote attacker could inject arbitrary HTML/Javascript code in a user's context and cause a crash, resulting in denial of service or potential execution of arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: phpldapadmin 1.2.2-6ubuntu1.1 After a standard system update you need to restart phpLDAPadmin to make all the necessary changes. References: https://usn.ubuntu.com/4620-1 CVE-2017-11107 Package Information: https://launchpad.net/ubuntu/+source/phpldapadmin/1.2.2-6ubuntu1.1