Common-Lisp-Controller Cache Arbitrary Code Injection Vulnerability
BID:14829
Info
Common-Lisp-Controller Cache Arbitrary Code Injection Vulnerability
| Bugtraq ID: | 14829 |
| Class: | Design Error |
| CVE: |
CVE-2005-2657 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 14 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | This vulnerability was announced in the referenced Debian advisory. |
| Vulnerable: |
common-lisp-controller common-lisp-controller |
| Not Vulnerable: | |
Discussion
Common-Lisp-Controller Cache Arbitrary Code Injection Vulnerability
common-lisp-controller is prone to an arbitrary code injection vulnerability.
Successful exploitation may facilitate privilege escalation; other attacks are also possible.
common-lisp-controller is prone to an arbitrary code injection vulnerability.
Successful exploitation may facilitate privilege escalation; other attacks are also possible.
Exploit / POC
Common-Lisp-Controller Cache Arbitrary Code Injection Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Common-Lisp-Controller Cache Arbitrary Code Injection Vulnerability
Solution:
Debian has released revised security advisory DSA 811-2 detailing fixes to address this issue. The fixes mentioned in the first revision (DSA 811-1) was prone to an error that caused third-party programs to fail. Please see the revised advisory for the most recent information regarding fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
common-lisp-controller common-lisp-controller
Solution:
Debian has released revised security advisory DSA 811-2 detailing fixes to address this issue. The fixes mentioned in the first revision (DSA 811-1) was prone to an error that caused third-party programs to fail. Please see the revised advisory for the most recent information regarding fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
common-lisp-controller common-lisp-controller
-
Debian common-lisp-controller_4.15sarge2_all.deb
http://security.debian.org/pool/updates/main/c/common-lisp-controller/ common-lisp-controller_4.15sarge2_all.deb -
Debian common-lisp-controller_4.15sarge3_all.deb
http://security.debian.org/pool/updates/main/c/common-lisp-controller/ common-lisp-controller_4.15sarge3_all.deb
References
Common-Lisp-Controller Cache Arbitrary Code Injection Vulnerability
References:
References:
- common-lisp-controller Homepage (common-lisp-controller)