Description
|
|
A vulnerability has been identified in Debian, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in Mojolicious, which could be exploited to conduct directory traversal attacks and disclose the contents of arbitrary files.
|
|
|
|
Vulnerable Products
|
|
Vulnerable Software: Debian GNU/Linux squeezeDebian GNU/Linux sid
|
|
|
|
Solution
|
|
Debian GNU/Linux squeeze - Upgrade to libmojolicious-perl version 0.999926-1+squeeze1Debian GNU/Linux sid - Upgrade to libmojolicious-perl version 1.16-1
|
|
|
|
CVE
|
|
CVE-2011-1589
|
|
|
|
References
|
|
http://lists.debian.org/debian-security-announce/2011/msg00090.html
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-1589
|
|
|
|
Vulnerability Manager Detection
|
|
No
|
|
|
|
IPS Protection
|
|
|
|
|
|