Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.58338
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 1287-1 (ldap-account-manager (0.4.9-2sarge1))
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to ldap-account-manager (0.4.9-2sarge1)
announced via advisory DSA 1287-1.

Two vulnerabilities have been identified in the version of
ldap-account-manager shipped with Debian 3.1 (sarge).

CVE-2006-7191
An untrusted PATH vulnerability could allow a local attacker to execute
arbitrary code with elevated privileges by providing a malicious rm
executable and specifying a PATH environment variable referencing this
executable.

CVE-2007-1840
Improper escaping of HTML content could allow an attacker to execute a
cross-site scripting attack (XSS) and execute arbitrary code in the
victim's browser in the security context of the affected web site.

For the old stable distribution (sarge), this problem has been fixed in
version 0.4.9-2sarge1. Newer versions of Debian (etch, lenny, and sid),
are not affected.

We recommend that you upgrade your ldap-account-manager package.

Solution:
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201287-1

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-7191
BugTraq ID: 23857
http://www.securityfocus.com/bid/23857
Debian Security Information: DSA-1287 (Google Search)
http://www.us.debian.org/security/2007/dsa-1287
http://secunia.com/advisories/25157
Common Vulnerability Exposure (CVE) ID: CVE-2007-1840
BugTraq ID: 23190
http://www.securityfocus.com/bid/23190
http://secunia.com/advisories/24687
http://www.vupen.com/english/advisories/2007/1149
XForce ISS Database: lam-htmlchar-xss(33307)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33307
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.