|Category:||Debian Local Security Checks|
|Title:||Debian Security Advisory DSA 704-1 (remstats)|
|Summary:||Debian Security Advisory DSA 704-1 (remstats)|
|Description:||The remote host is missing an update to remstats|
announced via advisory DSA 704-1.
Jens Steube discovered several vulnerabilities in remstats, the remote
statistics system. The Common Vulnerabilities and Exposures Project
identifies the following problems:
When processing uptime data on the unix-server a temporary file is
opened in an insecure fashion which could be used for a symlink
attack to create or overwrite arbitrary files with the permissions
of the remstats user.
The remoteping service can be exploited to execute arbitrary
commands due to missing input sanitising.
For the stable distribution (woody) these problems have been fixed in
For the unstable distribution (sid) these problems have been fixed in
We recommend that you upgrade your remstats packages.
Common Vulnerability Exposure (CVE) ID: CVE-2005-0387|
Debian Security Information: DSA-704 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2005-0388
|Copyright||Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com|
|This is only one of 38907 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.