Albatross Remote Arbitrary Code Execution Vulnerability
BID:16252
Info
Albatross Remote Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 16252 |
| Class: | Design Error |
| CVE: |
CVE-2006-0044 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2006 12:00AM |
| Updated: | Feb 20 2007 08:28PM |
| Credit: | The individual responsible for discovering this issue is not known. |
| Vulnerable: |
Albatross Albatross 1.33 Albatross Albatross 1.20 |
| Not Vulnerable: | |
Discussion
Albatross Remote Arbitrary Code Execution Vulnerability
Albatross is prone to an arbitrary code-execution vulnerability.
Reports indicate that malicious user-supplied data may be insecurely used as part of a template, which may lead to arbitrary code execution.
A remote attacker may exploit this issue to gain unauthorized access to an affected computer. Other attacks may be possible as well.
Albatross is prone to an arbitrary code-execution vulnerability.
Reports indicate that malicious user-supplied data may be insecurely used as part of a template, which may lead to arbitrary code execution.
A remote attacker may exploit this issue to gain unauthorized access to an affected computer. Other attacks may be possible as well.
Exploit / POC
Albatross Remote Arbitrary Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Albatross Remote Arbitrary Code Execution Vulnerability
Solution:
Debian has released advisory DSA 942-1 to address this issue. Please see the referenced advisory for more information.
Albatross 1.33 may not be vulnerable to this issue; Symantec could not confirm this.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Albatross Albatross 1.20
Solution:
Debian has released advisory DSA 942-1 to address this issue. Please see the referenced advisory for more information.
Albatross 1.33 may not be vulnerable to this issue; Symantec could not confirm this.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Albatross Albatross 1.20
-
Debian python-albatross-common_1.20-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/albatross/python-albatr oss-common_1.20-2_all.deb -
Debian python-albatross-doc_1.20-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/albatross/python-albatr oss-doc_1.20-2_all.deb -
Debian python-albatross_1.20-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/albatross/python-albatr oss_1.20-2_all.deb -
Debian python2.2-albatross_1.20-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/albatross/python2.2-alb atross_1.20-2_all.deb -
Debian python2.3-albatross_1.20-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/albatross/python2.3-alb atross_1.20-2_all.deb
References
Albatross Remote Arbitrary Code Execution Vulnerability
References:
References:
- Albatross Product Page (Albatross)