Nessus Plugin #14981
Plugin Index
Note: This file has been created from a
downloaded version of the Nessus Plugins
from
http://www.nessus.org/.
Therefore, the information here can be outdated.
[DSA144] DSA-144-1 wwwoffle
- Family:
- Debian Local Security Checks
- Category:
- infos
- Copyright:
- This script is (C) 2004 Michel Arboi
- Summary:
- DSA-144-1 wwwoffle
- Version:
- $Revision: 1.4 $
- Cve_id:
- CVE-2002-0818
- Bugtraq_id:
- 5260
- Xrefs:
- DSA:144
- Description:
A problem with wwwoffle has been discovered. The web proxy didn't
handle input data with negative Content-Length settings properly which
causes the processing child to crash. It is at this time not obvious
how this can lead to an exploitable vulnerability
however, it's better
to be safe than sorry, so here's an update.
Additionally, in the woody version empty passwords will be treated as
wrong when trying to authenticate. In the woody version we also
replaced CanonicaliseHost() with the latest routine from 2.7d, offered
by upstream. This stops bad IPv6 format IP addresses in URLs from
causing problems (memory overwriting, potential exploits).
This problem has been fixed in version 2.5c-10.4 for the old stable
distribution (potato), in version 2.7a-1.2 for the current stable
distribution (woody) and in version 2.7d-1 for the unstable
distribution (sid).
We recommend that you upgrade your wwwoffle packages.
Solution : http://www.debian.org/security/2002/dsa-144
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.