Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Debian 0.34.1-1 Moderate: DTC Multiple Issues Security Update

debian
Calendar Grey December 18, 2011
Scroller Debian
Uncover various weaknesses in DTC impacting Debian. Insights on resolutions and suggestions are included.
Ansgar Burchardt, Mike O'Connor and Philipp Kern discovered multiple vulnerabilities in DTC, a web control panel for admin and accounting hosting services:

Summary

Ansgar Burchardt, Mike O'Connor and Philipp Kern discovered multiple
vulnerabilities in DTC, a web control panel for admin and accounting
hosting services:

CVE-2011-3195

A possible shell insertion has been found in the mailing list
handling.

CVE-2011-3196

Unix rights for the apache2.conf were set incorrectly (world
readable).

CVE-2011-3197

Incorrect input sanitising for the $_SERVER["addrlink"] parameter
could lead to SQL insertion.

CVE-2011-3198

DTC was using the -b option of htpasswd, possibly revealing
password in clear text using ps or reading /proc.

CVE-2011-3199

A possible HTML/javascript insertion vulnerability has been found
in the DNS & MX section of the user panel.

This update also fixes several vulnerabilities, for which no CVE ID
has been assigned:

It has been discovered that DTC performs insufficient input sanitising
in the package installer, leading to possible unwanted destination
directory for installed packages if some DTC application packages
are...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: dtc
CVE ID: CVE-2011-3195 CVE-2011-3196 CVE-2011-3197 CVE-2011-3198

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.