Soluzioni per la vulnerabilità
| La Scansione Vulnerabilità periodica di WatchMouse verifica le vulnerabilità riportate qui sotto. Per visualizzare le soluzioni per la vulnerabilità più recenti scansionate da WatchMouse, visitare la pagina sulla panoramica delle Soluzioni per la vulnerabilità |
| Categoria: Debian Local Security Checks | Fattore di rischio: High | Aggiunto il: 1 lug 2009 |
| Synopsis: The remote host is missing the DSA-1824 security update Description: Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-1150 Cross site scripting vulnerability in the export page allow for an attacker that can place crafted cookies with the user to inject arbitrary web script or HTML. CVE-2009-1151 Static code injection allows for a remote attacker to inject arbitrary code into phpMyAdmin via the setup.php script. This script is in Debian under normal circumstances protected via Apache authentication. However, because of a recent worm based on this exploit, we are patching it regardless, to also protect installations that somehow still expose the setup.php script. For the old stable distribution (etch), these problems have been fixed in version 2.9.1.1-11. For the stable distribution (lenny), these problems have been fixed in version 2.11.8.1-5+lenny1. See also: http://www.debian.org/security/2009/dsa-1824 Solution: The Debian project recommends that you upgrade your phpmyadmin package. Risk factor: High / CVSS Base Score : 7.5 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P) |
||



