Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.56410
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1002-1)
Summary:The remote host is missing an update for the Debian 'webcalendar' package(s) announced via the DSA-1002-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'webcalendar' package(s) announced via the DSA-1002-1 advisory.

Vulnerability Insight:
Several security related problems have been discovered in webcalendar, a PHP based multi-user calendar. The Common Vulnerabilities and Exposures project identifies the following vulnerabilities:

CVE-2005-3949

Multiple SQL injection vulnerabilities allow remote attackers to execute arbitrary SQL commands.

CVE-2005-3961

Missing input sanitising allows an attacker to overwrite local files.

CVE-2005-3982

A CRLF injection vulnerability allows remote attackers to modify HTTP headers and conduct HTTP response splitting attacks.

The old stable distribution (woody) does not contain webcalendar packages.

For the stable distribution (sarge) these problems have been fixed in version 0.9.45-4sarge3.

For the unstable distribution (sid) these problems have been fixed in version 1.0.2-1.

We recommend that you upgrade your webcalendar package.

Affected Software/OS:
'webcalendar' package(s) on Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-3949
BugTraq ID: 15606
http://www.securityfocus.com/bid/15606
BugTraq ID: 15608
http://www.securityfocus.com/bid/15608
BugTraq ID: 15662
http://www.securityfocus.com/bid/15662
Bugtraq: 20051128 WebCalendar Multiple Vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/417900/100/0/threaded
Bugtraq: 20051201 WebCalendar Multiple Vulnerabilities. (Google Search)
http://www.securityfocus.com/archive/1/418286/100/0/threaded
Debian Security Information: DSA-1002 (Google Search)
http://www.debian.org/security/2006/dsa-1002
http://www.ush.it/2005/11/28/webcalendar-multiple-vulnerabilities
http://www.osvdb.org/21216
http://www.osvdb.org/21217
http://www.osvdb.org/21218
http://www.osvdb.org/21219
http://secunia.com/advisories/17784
http://secunia.com/advisories/19240
http://securityreason.com/securityalert/215
http://www.vupen.com/english/advisories/2005/2643
XForce ISS Database: webcalendar-multiple-scripts-sql-injection(23369)
https://exchange.xforce.ibmcloud.com/vulnerabilities/23369
Common Vulnerability Exposure (CVE) ID: CVE-2005-3961
http://www.osvdb.org/21220
XForce ISS Database: webcalendar-exporthandler-file-overwrite(23370)
https://exchange.xforce.ibmcloud.com/vulnerabilities/23370
Common Vulnerability Exposure (CVE) ID: CVE-2005-3982
BugTraq ID: 15673
http://www.securityfocus.com/bid/15673
http://vd.lwang.org/webcalendar_multiple_vulns.txt
http://www.osvdb.org/21383
http://secunia.com/advisories/17848
http://www.vupen.com/english/advisories/2005/2702
Common Vulnerability Exposure (CVE) ID: CVE-2005-3984
http://www.osvdb.org/21382
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.