PT-2005-5557 · Debian · Remstats-Doc+4
Jens Steube
·
Published
1970-01-01
·
Updated
2008-09-05
·
CVE-2005-0388
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
remstats versions 1.0.13 and earlier
remstats-bintools (affected versions not specified)
remstats-doc (affected versions not specified)
remstats-servers (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the remstats package of the Debian GNU/Linux operating system, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The remoteping service in remstats is specifically mentioned as having an unknown vulnerability that allows remote attackers to execute arbitrary commands due to missing input sanitizing.
Recommendations
For remstats versions 1.0.13 and earlier, consider updating to a version later than 1.0.13 as a fix.
For remstats-bintools, remstats-doc, and remstats-servers, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to these components to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Remstats
Remstats-Bintools
Remstats-Doc
Remstats-Servers