PT-2005-5557 · Debian · Remstats-Doc+4

Jens Steube

·

Publicado

1970-01-01

·

Atualizado

2008-09-05

·

CVE-2005-0388

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions remstats versions 1.0.13 and earlier remstats-bintools (affected versions not specified) remstats-doc (affected versions not specified) remstats-servers (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the remstats package of the Debian GNU/Linux operating system, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The remoteping service in remstats is specifically mentioned as having an unknown vulnerability that allows remote attackers to execute arbitrary commands due to missing input sanitizing.
Recommendations For remstats versions 1.0.13 and earlier, consider updating to a version later than 1.0.13 as a fix. For remstats-bintools, remstats-doc, and remstats-servers, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to these components to minimize the risk of exploitation.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-01342
BDU:2015-01343
BDU:2015-01344
BDU:2015-01345
CVE-2005-0388
DSA-704-1

Produtos afetados

Debian
Remstats
Remstats-Bintools
Remstats-Doc
Remstats-Servers