Boletines de Vulnerabilidades

DSA-3405 smokeping - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

Tero Marttila discovered that the Debian packaging for smokepinginstalled it in such a way that the CGI implementation of Apache httpd(mod_cgi) passed additional arguments to the smokeping_cgi program,potentially leading to arbitrary code execution in response to craftedHTTP requests.

More info:

https://www.debian.org/security/2015/dsa-3405

Identificadores estándar

Propiedad Valor
CVE CVE-2015-0859 and DSA-3405.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-11-27

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT