PT-2005-5557 · Debian · Remstats-Doc+4

Jens Steube

·

Published

1970-01-01

·

Updated

2008-09-05

·

CVE-2005-0388

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions remstats versions 1.0.13 and earlier remstats-bintools (affected versions not specified) remstats-doc (affected versions not specified) remstats-servers (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the remstats package of the Debian GNU/Linux operating system, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The remoteping service in remstats is specifically mentioned as having an unknown vulnerability that allows remote attackers to execute arbitrary commands due to missing input sanitizing.
Recommendations For remstats versions 1.0.13 and earlier, consider updating to a version later than 1.0.13 as a fix. For remstats-bintools, remstats-doc, and remstats-servers, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to these components to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01342
BDU:2015-01343
BDU:2015-01344
BDU:2015-01345
CVE-2005-0388
DSA-704-1

Affected Products

Debian
Remstats
Remstats-Bintools
Remstats-Doc
Remstats-Servers