Debian Apt-Cacher Remote Command Execution Vulnerability
BID:14459
Info
Debian Apt-Cacher Remote Command Execution Vulnerability
| Bugtraq ID: | 14459 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1854 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Eduard Bloch discovered this issue. |
| Vulnerable: |
Debian apt-cacher 0.9.9 Debian apt-cacher 0.9.4 |
| Not Vulnerable: |
Debian apt-cacher 0.9.10 Debian apt-cacher 0.9.4 sarge1 |
Discussion
Debian Apt-Cacher Remote Command Execution Vulnerability
apt-cacher is prone to a remote command execution vulnerability.
Specifically, the vulnerability can allow remote attackers to execute arbitrary commands on a computer that is acting as a caching host with the privileges of 'www-data'.
This may allow an attacker to gain unauthorized access to a vulnerable computer.
apt-cacher is prone to a remote command execution vulnerability.
Specifically, the vulnerability can allow remote attackers to execute arbitrary commands on a computer that is acting as a caching host with the privileges of 'www-data'.
This may allow an attacker to gain unauthorized access to a vulnerable computer.
Exploit / POC
Debian Apt-Cacher Remote Command Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Debian Apt-Cacher Remote Command Execution Vulnerability
Solution:
Debian has released advisory DSA 772-1 to address this issue. Please see the referenced advisory for more information.
Solution:
Debian has released advisory DSA 772-1 to address this issue. Please see the referenced advisory for more information.
References
Debian Apt-Cacher Remote Command Execution Vulnerability
References:
References: