| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.53120 |
| Kategorie: | Debian Local Security Checks |
| Titel: | Debian Security Advisory DSA 420-1 (jitterbug) |
| Zusammenfassung: | Debian Security Advisory DSA 420-1 (jitterbug) |
| Beschreibung: | The remote host is missing an update to jitterbug announced via advisory DSA 420-1. Steve Kemp discovered a security related problem in jitterbug, a simple CGI based bug tracking and reporting tool. Unfortunately not program executions use properly sanitized input which allows an attacker to execute arbitary commands on the server hosting the bug database. As mitigating factors these attacks are only available to non-guest users, and accounts for these people must be setup by the administrator making them trusted. For the stable distribution (woody) this problem has been fixed in version 1.6.2-4.2woody2. For the unstable distribution (sid) this problem has been fixed in version 1.6.2-4.5. We recommend that you upgrade your jitterbug package. Solution: http://www.securityspace.com/smysecure/catid.html?in=DSA%20420-1 |
| Querverweis: |
BugTraq ID: 9397 Common Vulnerability Exposure (CVE) ID: CVE-2004-0028 Debian Security Information: DSA-420 (Google Search) http://www.debian.org/security/2004/dsa-420 http://www.securityfocus.com/bid/9397 XForce ISS Database: jitterbug-execute-code(14207) http://xforce.iss.net/xforce/xfdb/14207 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|