LWN.net Logo

ajaxterm: denial of service

Package(s):ajaxterm CVE #(s):CVE-2009-1629
Created:February 12, 2010 Updated:December 30, 2010
Description: From the Debian advisory:

It was discovered that ajaxterm, a web-based terminal, generates weak and predictable session IDs, which might be used to hijack a session or cause a denial of service attack on a system that uses ajaxterm.

Alerts:
Fedora FEDORA-2010-18867 2010-12-13
Debian DSA-1994-1 2010-02-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds