PT-2006-1021 · Debian · Lurker

Publicado

2006-03-07

·

Atualizado

2017-07-20

·

CVE-2006-1064

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Lurker versions 2.0 and earlier
Description: The issue concerns multiple vulnerabilities in the Lurker package of the Debian GNU/Linux operating system, which can be exploited remotely to compromise the confidentiality of protected information. The vulnerabilities allow remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks.
Recommendations: For Lurker versions 2.0 and earlier, consider disabling the vulnerable components until a patch is available. Restrict access to the Lurker package to minimize the risk of exploitation. Avoid using the Lurker package in sensitive operations until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03288
CVE-2006-1064
DSA-999-1

Produtos afetados

Lurker