Summary
The remote host is missing an update to libapache-mod-python announced via advisory DSA 689-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20689-1
Insight
Graham Dumpleton discovered a flaw which can affect anyone using the publisher handle of the Apache Software Foundation's mod_python. The publisher handle lets you publish objects inside modules to make them callable via URL. The flaw allows a carefully crafted URL to obtain extra information that should not be visible (information leak).
For the stable distribution (woody) this problem has been fixed in version 2.7.8-0.0woody5.
For the unstable distribution (sid) this problem has been fixed in version 2.7.10-4 of libapache-mod-python and in version 3.1.3-3 of libapache2-mod-python.
We recommend that you upgrade your libapache-mod-python package.
Severity
Classification
-
CVE CVE-2005-0088 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities