| |||||||||||||
| ID de Prueba: | 1.3.6.1.4.1.25623.1.0.53120 |
| Categoría: | Debian Local Security Checks |
| Título: | Debian Security Advisory DSA 420-1 (jitterbug) |
| Resumen: | Debian Security Advisory DSA 420-1 (jitterbug) |
| Descripción: | The remote host is missing an update to jitterbug announced via advisory DSA 420-1. Steve Kemp discovered a security related problem in jitterbug, a simple CGI based bug tracking and reporting tool. Unfortunately not program executions use properly sanitized input which allows an attacker to execute arbitary commands on the server hosting the bug database. As mitigating factors these attacks are only available to non-guest users, and accounts for these people must be setup by the administrator making them trusted. For the stable distribution (woody) this problem has been fixed in version 1.6.2-4.2woody2. For the unstable distribution (sid) this problem has been fixed in version 1.6.2-4.5. We recommend that you upgrade your jitterbug package. Solution: http://www.securityspace.com/smysecure/catid.html?in=DSA%20420-1 |
| Referencia Cruzada: |
BugTraq ID: 9397 Common Vulnerability Exposure (CVE) ID: CVE-2004-0028 Debian Security Information: DSA-420 (Google Search) http://www.debian.org/security/2004/dsa-420 http://www.securityfocus.com/bid/9397 XForce ISS Database: jitterbug-execute-code(14207) http://xforce.iss.net/xforce/xfdb/14207 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| Esta es sólo una de 32582 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |
|