Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian: DSA 650-1 Urgent Update for Diatheke Command Execution Fix

debian
Calendar Grey January 20, 2005
Debian Logo
Critical command injection issue identified in diatheke CGI script on Debian due to lack of input filtering. Immediate upgrade required.
Ulf Härnhammar discovered that due to missing input sanitising in diatheke, a CGI script for making and browsing a bible website, it is possible to execute arbitrary commands vi...

Summary


For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you upgrade your diatheke package.


Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody

Size/MD5 checksum: 612 9204579e3a264d7d43297c1b7bf98438
Size/MD5 checksum: 21169 c355f97deb2ef2c39b82aec857b15a21
Size/MD5 checksum: 2389613 055f9c1e7c081a667674d9f4112abf11

Alpha architecture:

Size/MD5 checksum: 82154 2c73838e4e5d1112ded21365df2578a3
Size/MD5 checksum: 1712920 e3914e31b0b0217ac8f227f8730c0ace
...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here