Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA223] DSA-223-1 geneweb


Vulnerability Assessment Details

[DSA223] DSA-223-1 geneweb

Vulnerability Assessment Summary
DSA-223-1 geneweb

Detailed Explanation for this Vulnerability Assessment

A security issue has been discovered by Daniel de Rauglaudre, upstream
author of geneweb, a genealogical software with web interface. It
runs as a daemon on port 2317 by default. Paths are not properly
sanitized, so a carefully crafted URL lead geneweb to read and display
arbitrary files of the system it runs on.
For the current stable distribution (woody) this problem has been
fixed in version 4.06-2.
The old stable distribution (potato) is not affected.
For the unstable distribution (sid) this problem has been
fixed in version 4.09-1.
We recommend that you upgrade your geneweb package.


Solution : http://www.debian.org/security/2003/dsa-223
Network Security Threat Level: High

Networks Security ID: 6549

Vulnerability Assessment Copyright: This script is (C) 2005 Michel Arboi

Cables, Connectors

DELL POWEREDGE M1000E 16 X M610 BLADES 2 X INTEL QC X5550 32GB 300GB SAS
$26289.0
DELL POWEREDGE M1000E 16 X M610 BLADES 2 X INTEL QC X5550 32GB 300GB SAS pictureDELL POWEREDGE M1000E 2 X M610 BLADES 2 X E5620 2.40GHZ 16GB RAM 1 X 160GB SATA
$9949.0
DELL POWEREDGE M1000E 2 X M610 BLADES 2 X E5620 2.40GHZ 16GB RAM 1 X 160GB SATA pictureDELL POWEREDGE M1000E 8 X M610 BLADES 1 X E5506 2.13GHZ 3GB RAM NO HDD
$13489.0
DELL POWEREDGE M1000E 8 X M610 BLADES 1 X E5506 2.13GHZ 3GB RAM NO HDD pictureDELL POWEREDGE M1000E 8 X M610 BLADES 1 X E5620 2.40GHZ 12GB RAM NO HDD
$14789.0
DELL POWEREDGE M1000E 8 X M610 BLADES 1 X E5620 2.40GHZ 12GB RAM NO HDD picture


Discussions

No Discussions have been posted on this vulnerability.