PT-2005-5557 · Debian · Remstats-Doc+4
Jens Steube
·
Publicado
1970-01-01
·
Atualizado
2008-09-05
·
CVE-2005-0388
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
remstats versions 1.0.13 and earlier
remstats-bintools (affected versions not specified)
remstats-doc (affected versions not specified)
remstats-servers (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the remstats package of the Debian GNU/Linux operating system, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The remoteping service in remstats is specifically mentioned as having an unknown vulnerability that allows remote attackers to execute arbitrary commands due to missing input sanitizing.
Recommendations
For remstats versions 1.0.13 and earlier, consider updating to a version later than 1.0.13 as a fix.
For remstats-bintools, remstats-doc, and remstats-servers, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to these components to minimize the risk of exploitation.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Debian
Remstats
Remstats-Bintools
Remstats-Doc
Remstats-Servers