LWN.net Logo

geneweb - information exposure

Package(s):geneweb CVE #(s):CAN-2002-1390
Created:January 7, 2003 Updated:January 8, 2003
Description: A security issue has been discovered by Daniel de Rauglaudre, upstream author of geneweb, a genealogical software with web interface. It runs as a daemon on port 2317 by default. Paths are not properly sanitized, so a carefully crafted URL leads geneweb to read and display arbitrary files of the system it runs on.
Alerts:
Debian DSA-223-1 2003-01-07

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds