EKG Unspecified Command Execution Vulnerability
BID:14308
Info
EKG Unspecified Command Execution Vulnerability
| Bugtraq ID: | 14308 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1851 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Marcin Owsiany and Wojtek Kaniewski. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 ekg ekg 2005-04-11 |
| Not Vulnerable: |
ekg ekg 1.6 rc3 ekg ekg 1.6 rc2 |
Discussion
EKG Unspecified Command Execution Vulnerability
ekg is affected by an unspecified command execution vulnerability.
A successful attack would involve executing shell commands in the context of the application. It may be possible for an attacker to gain unauthorized access to an affected computer by exploiting this issue.
ekg is affected by an unspecified command execution vulnerability.
A successful attack would involve executing shell commands in the context of the application. It may be possible for an attacker to gain unauthorized access to an affected computer by exploiting this issue.
Exploit / POC
EKG Unspecified Command Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
EKG Unspecified Command Execution Vulnerability
Solution:
Debian has released advisory DSA 760-1 to address this issue. Please see the referenced advisory for more information.
Ubuntu Linux has released advisory USN-162-1, along with fixes to address various issues. Please see the referenced advisory for further information.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
The vendor has addressed this and other issues in ekg version 1.6rc2 and later:
ekg ekg 2005-04-11
Solution:
Debian has released advisory DSA 760-1 to address this issue. Please see the referenced advisory for more information.
Ubuntu Linux has released advisory USN-162-1, along with fixes to address various issues. Please see the referenced advisory for further information.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
The vendor has addressed this and other issues in ekg version 1.6rc2 and later:
ekg ekg 2005-04-11
-
ekg ekg-1.6rc3.tar.gz
http://dev.null.pl/ekg/ekg-1.6rc3.tar.gz
References
EKG Unspecified Command Execution Vulnerability
References:
References:
- ekg Homepage (ekg)
- Multiple vulnerabilities in libgadu and ekg package (Wojtek Kaniewski
)