Enemies of Carlotta Shell Argument Command Execution Vulnerability
BID:21572
Info
Enemies of Carlotta Shell Argument Command Execution Vulnerability
| Bugtraq ID: | 21572 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5875 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2006 12:00AM |
| Updated: | Dec 14 2006 03:53PM |
| Credit: | Antti-Juhani Kaijanaho is credited with the discovery of this issue. |
| Vulnerable: |
Enemies of Carlotta Enemies of Carlotta 1.2.3 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha |
| Not Vulnerable: |
Enemies of Carlotta Enemies of Carlotta 1.2.4 |
Discussion
Enemies of Carlotta Shell Argument Command Execution Vulnerability
Enemies of Carlotta is prone to a command-execution vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker could exploit this issue to execute arbitrary shell commands in the context of the application.
Enemies of Carlotta is prone to a command-execution vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker could exploit this issue to execute arbitrary shell commands in the context of the application.
Exploit / POC
Enemies of Carlotta Shell Argument Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution / Fix
Enemies of Carlotta Shell Argument Command Execution Vulnerability
Solution:
The vendor has released a fix that addresses this issue; please see the references for more information.
Enemies of Carlotta Enemies of Carlotta 1.2.3
Debian Linux 3.1 ia-32
Debian Linux 3.1 ppc
Debian Linux 3.1 alpha
Debian Linux 3.1 m68k
Debian Linux 3.1 ia-64
Debian Linux 3.1 mipsel
Debian Linux 3.1 arm
Debian Linux 3.1 mips
Debian Linux 3.1 s/390
Debian Linux 3.1 amd64
Debian Linux 3.1 hppa
Debian Linux 3.1 sparc
Solution:
The vendor has released a fix that addresses this issue; please see the references for more information.
Enemies of Carlotta Enemies of Carlotta 1.2.3
-
Enemies of Carlotta enemies-of-carlotta-1.2.4.tar.gz
http://liw.iki.fi/liw/eoc/enemies-of-carlotta-1.2.4.tar.gz
Debian Linux 3.1 ia-32
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 ppc
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 alpha
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 m68k
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 ia-64
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 mipsel
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 arm
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 mips
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 s/390
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 amd64
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 hppa
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
Debian Linux 3.1 sparc
-
Debian enemies-of-carlotta_1.0.3.orig.tar.gz (debian)
http://security.debian.org/pool/updates/main/e/enemies-of-carlotta/ene mies-of-carlotta_1.0.3.orig.tar.gz
References
Enemies of Carlotta Shell Argument Command Execution Vulnerability
References:
References:
- Product Homepage (Enemies of Carlotta)
- EoC 1.2.4 -- security problem fixed, please upgrade immediately (Lars Wirzenius)