exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Secunia Security Advisory 23580

Secunia Security Advisory 23580
Posted Dec 29, 2006
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Debian has issued an update for elog. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and cause a DoS (Denial of Service), and malicious users to conduct script insertion attacks, cause a DoS, and potentially compromise a vulnerable system.

tags | advisory, denial of service, vulnerability, xss
systems | linux, debian
SHA-256 | 400b602bd3a4652f70f20e52f1a09a93849687d7afcd4e4ffbb280ff480a257b

Secunia Security Advisory 23580

Change Mirror Download


----------------------------------------------------------------------

Secunia is proud to announce the availability of the Secunia Software
Inspector.

The Secunia Software Inspector is a free service that detects insecure
versions of software that you may have installed in your system. When
insecure versions are detected, the Secunia Software Inspector also
provides thorough guidelines for updating the software to the latest
secure version from the vendor.

Try it out online:
http://secunia.com/software_inspector/

----------------------------------------------------------------------

TITLE:
Debian update for elog

SECUNIA ADVISORY ID:
SA23580

VERIFY ADVISORY:
http://secunia.com/advisories/23580/

CRITICAL:
Moderately critical

IMPACT:
Cross Site Scripting, DoS, System access

WHERE:
>From remote

OPERATING SYSTEM:
Debian GNU/Linux 3.1
http://secunia.com/product/5307/
Debian GNU/Linux unstable alias sid
http://secunia.com/product/530/

DESCRIPTION:
Debian has issued an update for elog. This fixes some
vulnerabilities, which can be exploited by malicious people to
conduct cross-site scripting attacks and cause a DoS (Denial of
Service), and malicious users to conduct script insertion attacks,
cause a DoS, and potentially compromise a vulnerable system.

For more information:
SA22057
SA22638
SA22800

SOLUTION:
Apply updated packages.

-- Debian GNU/Linux 3.1 alias sarge --

Source archives:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3.dsc
Size/MD5 checksum: 581 c072e867caa0058ac44cbd69c6afff51
http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3.diff.gz
Size/MD5 checksum: 23758 0718302e60a98844f27cd6eab336c5ce
http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558.orig.tar.gz
Size/MD5 checksum: 538216 e05c9fdaa02692ce20c70a5fd2748fe3

Alpha architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_alpha.deb
Size/MD5 checksum: 556190 081bd3b98bea9516c26b487024d6140f

AMD64 architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_amd64.deb
Size/MD5 checksum: 512510 48ee1c675cefa6a0b0af01f7cbb9f079

ARM architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_arm.deb
Size/MD5 checksum: 517072 5e4a4dc726a8a0bf75f05de3fe17e07c

HP Precision architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_hppa.deb
Size/MD5 checksum: 544448 5f5c83341837c6dd18211b4164bbd1dc

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_i386.deb
Size/MD5 checksum: 514786 c14108b91d171ac38b0104ae769cfc96

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_ia64.deb
Size/MD5 checksum: 598224 df22b05edfb9dfab43cc69233f2d88e4

Motorola 680x0 architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_m68k.deb
Size/MD5 checksum: 482826 254d8a1f1cae62719a9f6f2a461cffd8

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_mips.deb
Size/MD5 checksum: 522074 909b22df0ac8302bd7b00b8338511198

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_mipsel.deb
Size/MD5 checksum: 525164 278bc7397817c8f6a8a44d2879f0682c

PowerPC architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_powerpc.deb
Size/MD5 checksum: 524304 37438b8fff9c0b162aa6870fd5c7ba31

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_s390.deb
Size/MD5 checksum: 515148 32cf397b104321646de736141a90354d

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/e/elog/elog_2.5.7+r1558-4+sarge3_sparc.deb
Size/MD5 checksum: 519788 b532c963d03d66f4e32861531adefe4e

-- Debian GNU/Linux unstable alias sid --

Fixed in version 2.6.2+r1754-1.

ORIGINAL ADVISORY:
http://www.us.debian.org/security/2006/dsa-1242

OTHER REFERENCES:
SA22057:
http://secunia.com/advisories/22057/

SA22638:
http://secunia.com/advisories/22638/

SA22800:
http://secunia.com/advisories/22800/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    42 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close