DEBIAN-CVE-2007-1840

Source
https://security-tracker.debian.org/tracker/CVE-2007-1840
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2007-1840.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2007-1840
Upstream
Published
2007-04-03T00:19:00Z
Modified
2025-09-19T06:22:44Z
Summary
[none]
Details

lib/modules.inc in LDAP Account Manager (LAM) before 1.3.0 does not escape HTML special characters in LDAP data, which allows remote attackers to have an unknown impact, probably cross-site scripting (XSS).

References

Affected packages

Debian:11 / ldap-account-manager

Package

Name
ldap-account-manager
Purl
pkg:deb/debian/ldap-account-manager?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.1-2

Ecosystem specific

{
    "urgency": "medium"
}

Debian:12 / ldap-account-manager

Package

Name
ldap-account-manager
Purl
pkg:deb/debian/ldap-account-manager?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.1-2

Ecosystem specific

{
    "urgency": "medium"
}

Debian:13 / ldap-account-manager

Package

Name
ldap-account-manager
Purl
pkg:deb/debian/ldap-account-manager?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.1-2

Ecosystem specific

{
    "urgency": "medium"
}

Debian:14 / ldap-account-manager

Package

Name
ldap-account-manager
Purl
pkg:deb/debian/ldap-account-manager?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.1-2

Ecosystem specific

{
    "urgency": "medium"
}