Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64416
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1829-1)
Summary:The remote host is missing an update for the Debian 'sork-passwd-h3' package(s) announced via the DSA-1829-1 advisory.;; This VT has been deprecated and merged into the VT 'deb_1829.nasl' (OID: 1.3.6.1.4.1.25623.1.0.64416).
Description:Summary:
The remote host is missing an update for the Debian 'sork-passwd-h3' package(s) announced via the DSA-1829-1 advisory.

This VT has been deprecated and merged into the VT 'deb_1829.nasl' (OID: 1.3.6.1.4.1.25623.1.0.64416).

Vulnerability Insight:
It was discovered that sork-passwd-h3, a Horde3 module for users to change their password, is prone to a cross-site scripting attack via the backend parameter.

For the oldstable distribution (etch), this problem has been fixed in version 3.0-2+etch1.

For the stable distribution (lenny), this problem has been fixed in version 3.0-2+lenny1.

For the testing distribution (squeeze), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in version 3.1-1.1.

We recommend that you upgrade your sork-passwd-h3 packages.

Affected Software/OS:
'sork-passwd-h3' package(s) on Debian 4, Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-2360
BugTraq ID: 35573
http://www.securityfocus.com/bid/35573
Debian Security Information: DSA-1829 (Google Search)
http://www.debian.org/security/2009/dsa-1829
http://lists.horde.org/archives/announce/2009/000507.html
http://secunia.com/advisories/35720
http://secunia.com/advisories/35769
http://www.vupen.com/english/advisories/2009/1784
XForce ISS Database: passwd-main-xss(51542)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51542
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.