Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.702997
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 2997-1 (reportbug - security update)
Zusammenfassung:Jakub Wilk discovered a remote command execution flaw in reportbug, a;tool to report bugs in the Debian distribution. A man-in-the-middle;attacker could put shell metacharacters in the version number allowing;arbitrary code execution with the privileges of the user running;reportbug.
Beschreibung:Summary:
Jakub Wilk discovered a remote command execution flaw in reportbug, a
tool to report bugs in the Debian distribution. A man-in-the-middle
attacker could put shell metacharacters in the version number allowing
arbitrary code execution with the privileges of the user running
reportbug.

Affected Software/OS:
reportbug on Debian Linux

Solution:
For the stable distribution (wheezy), this problem has been fixed in
version 6.4.4+deb7u1.

For the testing distribution (jessie), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 6.5.0+nmu1.

We recommend that you upgrade your reportbug packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-0479
BugTraq ID: 69055
http://www.securityfocus.com/bid/69055
Debian Security Information: DSA-2997 (Google Search)
http://www.debian.org/security/2014/dsa-2997
http://www.osvdb.org/109858
http://secunia.com/advisories/59896
XForce ISS Database: reportbug-cve20140479-code-exec(95149)
https://exchange.xforce.ibmcloud.com/vulnerabilities/95149
CopyrightCopyright (c) 2014 Greenbone Networks GmbH http://greenbone.net

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.