Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.63167
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: verlihub
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: verlihub

CVE-2008-5705
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger
mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier, when user
triggers are enabled, allows remote attackers to execute arbitrary
commands via shell metacharacters in an argument.

CVE-2008-5706
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger
mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows
local users to overwrite arbitrary files via a symlink attack on the
/tmp/trigger.tmp temporary file.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2008-5705
BugTraq ID: 32420
http://www.securityfocus.com/bid/32420
https://www.exploit-db.com/exploits/7183
http://bugs.debian.org/506530
http://openwall.com/lists/oss-security/2008/12/17/16
http://securityreason.com/securityalert/4800
XForce ISS Database: verlihub-trigger-command-execution(46801)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46801
Common Vulnerability Exposure (CVE) ID: CVE-2008-5706
BugTraq ID: 32889
http://www.securityfocus.com/bid/32889
CopyrightCopyright (C) 2009 E-Soft Inc.

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.