Summary
The remote host is missing an update to tdiary
announced via advisory DSA 808-1.
The tdiary Development Team has discovered a Cross-Site Request Forgery (CSRF) vulnerability in tdiary, a new generation weblog that can be exploited by remote attackers to alter the users information.
The old stable distribution (woody) does not contain tdiary packages.
Solution
For the stable distribution (sarge) this problem has been fixed in version 2.0.1-1sarge1.
For the unstable distribution (sid) this problem has been fixed in version 2.0.2-1.
We recommend that you upgrade your tdiary packages.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20808-1
Severity
Classification
-
CVE CVE-2005-2411 -
CVSS Base Score: 5.1
AV:N/AC:H/Au:N/C:P/I:P/A:P
Related Vulnerabilities