CVE-2015-5349

NameCVE-2015-5349
DescriptionThe CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache-directory-server (PTS)bullseye2.0.0~M24-4fixed
bookworm2.0.0~M26-1fixed
sid, trixie2.0.0~M26-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache-directory-serversource(unstable)(not affected)

Notes

- apache-directory-server <not-affected> (Fixed before initial upload to Debian)

Search for package or bug name: Reporting problems