LWN.net Logo

dtc: multiple vulnerabilities

Package(s):dtc CVE #(s):CVE-2011-3195 CVE-2011-3196 CVE-2011-3197 CVE-2011-3198 CVE-2011-3199
Created:December 19, 2011 Updated:December 21, 2011
Description: From the Debian advisory:

Ansgar Burchardt, Mike O'Connor and Philipp Kern discovered multiple vulnerabilities in DTC, a web control panel for admin and accounting hosting services:

CVE-2011-3195: A possible shell insertion has been found in the mailing list handling.

CVE-2011-3196: Unix rights for the apache2.conf were set incorrectly (world readable).

CVE-2011-3197: Incorrect input sanitising for the $_SERVER["addrlink"] parameter could lead to SQL insertion.

CVE-2011-3198: DTC was using the -b option of htpasswd, possibly revealing password in clear text using ps or reading /proc.

CVE-2011-3199: A possible HTML/javascript insertion vulnerability has been found in the DNS & MX section of the user panel.

Alerts:
Debian DSA-2365-1 2011-12-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds