Summary
The remote host is missing an update to jitterbug
announced via advisory DSA 420-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20420-1
Insight
Steve Kemp discovered a security related problem in jitterbug, a simple CGI based bug tracking and reporting tool. Unfortunately not program executions use properly sanitized input which allows an attacker to execute arbitary commands on the server hosting the bug database. As mitigating factors these attacks are only available to non-guest users, and accounts for these people must be setup by the administrator making them trusted.
For the stable distribution (woody) this problem has been fixed in version 1.6.2-4.2woody2.
For the unstable distribution (sid) this problem has been fixed in version 1.6.2-4.5.
We recommend that you upgrade your jitterbug package.
Severity
Classification
-
CVE CVE-2004-0028 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities