| |||||||||||||
| ID de Prueba: | 1.3.6.1.4.1.25623.1.0.66516 |
| Categoría: | Debian Local Security Checks |
| Título: | Debian Security Advisory DSA 1949-1 (php-net-ping) |
| Resumen: | Debian Security Advisory DSA 1949-1 (php-net-ping) |
| Descripción: | The remote host is missing an update to php-net-ping announced via advisory DSA 1949-1. It was discovered that php-net-ping, a PHP PEAR module to execute ping independently of the Operating System, performs insufficient input sanitising, which might be used to inject arguments (no CVE yet) or execute arbitrary commands (CVE-2009-4024) on a system that uses php-net-ping. For the stable distribution (lenny), this problem has been fixed in version 2.4.2-1+lenny1. For the oldstable distribution (etch), this problem has been fixed in version 2.4.2-1+etch1. For the testing distribution (squeeze), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 2.4.2-1.1. We recommend that you upgrade your php-net-ping packages. Solution: http://www.securityspace.com/smysecure/catid.html?in=DSA%201949-1 |
| Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-4024 Debian Security Information: DSA-1949 (Google Search) http://www.debian.org/security/2009/dsa-1949 https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01044.html https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01152.html https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01130.html BugTraq ID: 37093 http://www.securityfocus.com/bid/37093 http://secunia.com/advisories/37451 http://secunia.com/advisories/37502 http://www.vupen.com/english/advisories/2009/3320 XForce ISS Database: netping-ping-command-execution(54390) http://xforce.iss.net/xforce/xfdb/54390 |
| Copyright | Copyright (c) 2009 E-Soft Inc. http://www.securityspace.com |
| Esta es sólo una de 32582 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |
|