GeneWeb Maintainer Scripts Unspecified Insecure File Operations Vulnerability
BID:13262
Info
GeneWeb Maintainer Scripts Unspecified Insecure File Operations Vulnerability
| Bugtraq ID: | 13262 |
| Class: | Unknown |
| CVE: |
CVE-2005-0391 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 19 2005 12:00AM |
| Updated: | Jul 12 2009 02:06PM |
| Credit: | Discovery of this issue is credited to Tim Dijkstra. |
| Vulnerable: |
GeneWeb GeneWeb 4.0 9 GeneWeb GeneWeb 4.0 8 GeneWeb GeneWeb 4.0 7 GeneWeb GeneWeb 4.0 6 GeneWeb GeneWeb 4.0 5 |
| Not Vulnerable: | |
Discussion
GeneWeb Maintainer Scripts Unspecified Insecure File Operations Vulnerability
GeneWeb ships with maintainer scripts that are employed when upgrading or installing the software.
The GeneWeb maintainer scripts are reported prone to an unspecified insecure file operation.
This issue may lead to modification of arbitrary files with the context of the user that is running the maintainer scripts.
GeneWeb ships with maintainer scripts that are employed when upgrading or installing the software.
The GeneWeb maintainer scripts are reported prone to an unspecified insecure file operation.
This issue may lead to modification of arbitrary files with the context of the user that is running the maintainer scripts.
Exploit / POC
GeneWeb Maintainer Scripts Unspecified Insecure File Operations Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GeneWeb Maintainer Scripts Unspecified Insecure File Operations Vulnerability
Solution:
Debian has released an advisory (DSA 712-1) and updates to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
GeneWeb GeneWeb 4.0 6
Solution:
Debian has released an advisory (DSA 712-1) and updates to address this issue. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
GeneWeb GeneWeb 4.0 6
-
Debian geneweb_4.06-2woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_alpha.deb -
Debian geneweb_4.06-2woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_arm.deb -
Debian geneweb_4.06-2woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_hppa.deb -
Debian geneweb_4.06-2woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_i386.deb -
Debian geneweb_4.06-2woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_ia64.deb -
Debian geneweb_4.06-2woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_m68k.deb -
Debian geneweb_4.06-2woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_mips.deb -
Debian geneweb_4.06-2woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_mipsel.deb -
Debian geneweb_4.06-2woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_powerpc.deb -
Debian geneweb_4.06-2woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_s390.deb -
Debian geneweb_4.06-2woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/geneweb_4.06-2w oody1_sparc.deb -
Debian gwtp_4.06-2woody1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_alpha.deb -
Debian gwtp_4.06-2woody1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_arm.deb -
Debian gwtp_4.06-2woody1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_hppa.deb -
Debian gwtp_4.06-2woody1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_i386.deb -
Debian gwtp_4.06-2woody1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_ia64.deb -
Debian gwtp_4.06-2woody1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_m68k.deb -
Debian gwtp_4.06-2woody1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_mips.deb -
Debian gwtp_4.06-2woody1_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_mipsel.deb -
Debian gwtp_4.06-2woody1_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_powerpc.deb -
Debian gwtp_4.06-2woody1_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_s390.deb -
Debian gwtp_4.06-2woody1_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/g/geneweb/gwtp_4.06-2wood y1_sparc.deb
References
GeneWeb Maintainer Scripts Unspecified Insecure File Operations Vulnerability
References:
References:
- GeneWeb Home Page (GeneWeb)