Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.66126
Category:Mandrake Local Security Checks
Title:Mandriva Security Advisory MDVSA-2009:291 (jetty5)
Summary:The remote host is missing an update to jetty5;announced via advisory MDVSA-2009:291.
Description:Summary:
The remote host is missing an update to jetty5
announced via advisory MDVSA-2009:291.

Vulnerability Insight:
A vulnerability has been identified and corrected in jetty5:

Directory traversal vulnerability in the HTTP server in Mort Bay
Jetty before 6.1.17, and 7.0.0.M2 and earlier 7.x versions, allows
remote attackers to access arbitrary files via directory traversal
sequences in the URI (CVE-2009-1523).

This update fixes this vulnerability.

Affected: 2009.0, 2009.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-1523
BugTraq ID: 34800
http://www.securityfocus.com/bid/34800
BugTraq ID: 35675
http://www.securityfocus.com/bid/35675
CERT/CC vulnerability note: VU#402580
http://www.kb.cert.org/vuls/id/402580
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01257.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01259.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01262.html
HPdes Security Advisory: HPSBMA02553
http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388
HPdes Security Advisory: SSRT100184
http://www.securitytracker.com/id?1022563
http://secunia.com/advisories/34975
http://secunia.com/advisories/35143
http://secunia.com/advisories/35225
http://secunia.com/advisories/35776
http://secunia.com/advisories/40553
http://www.vupen.com/english/advisories/2009/1900
http://www.vupen.com/english/advisories/2010/1792
CopyrightCopyright (C) 2009 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.