| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.71141 |
| Kategorie: | Debian Local Security Checks |
| Titel: | Debian Security Advisory DSA 2414-1 (fex) |
| Zusammenfassung: | Debian Security Advisory DSA 2414-1 (fex) |
| Beschreibung: | The remote host is missing an update to fex announced via advisory DSA 2414-1. Nicola Fioravanti discovered that F*X, a web service for transferring very large files, is not properly sanitizing input parameters of the fup script. An attacker can use this flaw to conduct reflected cross-site scripting attacks via various script parameters. For the stable distribution (squeeze), this problem has been fixed in version 20100208+debian1-1+squeeze2. For the testing distribution (wheezy), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 20120215-1. We recommend that you upgrade your fex packages. Solution: http://www.securityspace.com/smysecure/catid.html?in=DSA%202414-1 |
| Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2012-0869 Bugtraq: 20120220 Re: Vulnerabilitites in Debian F*EX <= 20100208 and F*EX 20111129-2. (Google Search) http://archives.neohapsis.com/archives/bugtraq/2012-02/0112.html Bugtraq: 20120220 Vulnerabilitites in Debian F*EX <= 20100208 and F*EX 20111129-2. (Google Search) http://archives.neohapsis.com/archives/bugtraq/2012-02/0109.html http://www.openwall.com/lists/oss-security/2012/02/20/8 http://www.openwall.com/lists/oss-security/2012/02/20/1 http://www.openwall.com/lists/oss-security/2012/02/23/2 Debian Security Information: DSA-2414 (Google Search) http://www.debian.org/security/2012/dsa-2414 BugTraq ID: 52085 http://www.securityfocus.com/bid/52085 http://osvdb.org/79420 http://secunia.com/advisories/47971 XForce ISS Database: fastfileexchange-fup-id-xss(78966) http://xforce.iss.net/xforce/xfdb/78966 |
| Copyright | Copyright (c) 2012 E-Soft Inc. http://www.securityspace.com |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|