Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.702997
Categoría:Debian Local Security Checks
Título:Debian Security Advisory DSA 2997-1 (reportbug - security update)
Resumen:Jakub Wilk discovered a remote command execution flaw in reportbug, a;tool to report bugs in the Debian distribution. A man-in-the-middle;attacker could put shell metacharacters in the version number allowing;arbitrary code execution with the privileges of the user running;reportbug.
Descripción:Summary:
Jakub Wilk discovered a remote command execution flaw in reportbug, a
tool to report bugs in the Debian distribution. A man-in-the-middle
attacker could put shell metacharacters in the version number allowing
arbitrary code execution with the privileges of the user running
reportbug.

Affected Software/OS:
reportbug on Debian Linux

Solution:
For the stable distribution (wheezy), this problem has been fixed in
version 6.4.4+deb7u1.

For the testing distribution (jessie), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in
version 6.5.0+nmu1.

We recommend that you upgrade your reportbug packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2014-0479
BugTraq ID: 69055
http://www.securityfocus.com/bid/69055
Debian Security Information: DSA-2997 (Google Search)
http://www.debian.org/security/2014/dsa-2997
http://www.osvdb.org/109858
http://secunia.com/advisories/59896
XForce ISS Database: reportbug-cve20140479-code-exec(95149)
https://exchange.xforce.ibmcloud.com/vulnerabilities/95149
CopyrightCopyright (c) 2014 Greenbone Networks GmbH http://greenbone.net

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.