Summary
The remote host is missing an update to phpgedview announced via advisory DSA 1580-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201580-1
Insight
It was discovered that phpGedView, an application to provide online access to genealogical data, allowed remote attackers to gain administrator privileges due to a programming error.
Note: this problem was a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems.
Resolving this problem was only possible by completely reworking the API, which is not considered appropriate for a security update. Since these are peripheral functions probably not used by the large majority of package users, it was decided to remove these interfaces. If you require that interface nonetheless, you are advised to use a version of phpGedView backported from Debian Lenny, which has a completely redesigned API.
For the stable distribution (etch), this problem has been fixed in version 4.0.2.dfsg-4.
For the unstable distribution (sid), this problem has been fixed in version 4.1.e+4.1.5-1.
We recommend that you upgrade your phpgedview package.
Severity
Classification
-
CVE CVE-2008-2064 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities