Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2010-017

Mandriva Linux Security Advisory 2010-017 – WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window’s title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct this issue.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/85404/MDVSA-2010-017.txt

Source: https://packetstormsecurity.com/files/85404/Mandriva-Linux-Security-Advisory-2010-017.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534