{"id":"MGASA-2015-0017","summary":"Updated glpi package fixes security vulnerabilities","details":"Updated glpi package fixes security vulnerabilities:\n\nDue to a bug in GLPI before 0.84.7, a user without access to cost information\ncan in fact see the information when selecting cost as a search criteria\n(CVE-2014-5032).\n\nAn issue in GLPI before 0.84.8 may allow arbitrary local files to be included\nby PHP through an autoload function (CVE-2014-8360).\n\nSQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1\nallows remote authenticated users to execute arbitrary SQL commands via the\ncondition parameter (CVE-2014-9258).\n","modified":"2026-04-16T06:23:31.769637289Z","published":"2015-01-09T16:44:12Z","upstream":["CVE-2014-5032","CVE-2014-8360","CVE-2014-9258"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0017.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14933"},{"type":"WEB","url":"http://www.glpi-project.org/spip.php?page=annonce&id_breve=326&lang=en"},{"type":"WEB","url":"http://www.glpi-project.org/spip.php?page=annonce&id_breve=330&lang=en"},{"type":"WEB","url":"http://www.glpi-project.org/spip.php?page=annonce&id_breve=334&lang=en"},{"type":"WEB","url":"http://tlk.tuxfamily.org/doku.php?id=writeup:cve-2014-8360"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2015-January/147296.html"}],"affected":[{"package":{"name":"glpi","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/glpi?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.84.3-1.2.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0017.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}