LWN.net Logo

maxdb: arbitrary code execution

Package(s):maxdb CVE #(s):CVE-2006-4305
Created:October 5, 2006 Updated:October 11, 2006
Description: Version 7.5.00 of the MaxDB database has a vulnerability in the WebDBM frontend. Insufficient input sanitization is performed on data passed to the frontend, resulting in the possible execution of arbitrary code.
Alerts:
Debian DSA-1190-1 2006-10-04

(Log in to post comments)

maxdb: arbitrary code execution

Posted Oct 12, 2006 3:40 UTC (Thu) by branden (subscriber, #7029) [Link]

The DSA ID for this issue appears to be "DSA-1190-1", not "DSA-1XXX-1".

To my disappointment, I found nothing XXX-rated in the advisory text.

LWN, could you correct your reference, please? :)

maxdb: arbitrary code execution

Posted Oct 12, 2006 17:02 UTC (Thu) by ris (editor, #5) [Link]

> The DSA ID for this issue appears to be "DSA-1190-1", not "DSA-1XXX-1".

I've fixed it in our database. We just repeated what was sent.

http://lists.debian.org/debian-security-announce/debian-s...

says Debian Security Advisory DSA 1XXX-1
Rebecca

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds