LWN.net Logo

jitterbug: improperly sanitized input

Package(s):jitterbug CVE #(s):CAN-2004-0028
Created:January 12, 2004 Updated:January 14, 2004
Description: Steve Kemp discovered a security related problem in jitterbug, a simple CGI based bug tracking and reporting tool. Program executions may use improperly sanitized input which allows an attacker to execute arbitrary commands on the server hosting the bug database. As mitigating factors these attacks are only available to non-guest users, and accounts for these people must be setup by the administrator making them "trusted".
Alerts:
Debian DSA-420-1 2004-01-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds