Family: Debian Local Security Checks --> Category: infos
[DSA144] DSA-144-1 wwwoffle Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
A problem with wwwoffle has been discovered. The web proxy didn't
handle input data with negative Content-Length settings properly which
causes the processing child to crash. It is at this time not obvious
how this can lead to an exploitable vulnerability
however, it's better
to be safe than sorry, so here's an update.
Additionally, in the woody version empty passwords will be treated as
wrong when trying to authenticate. In the woody version we also
replaced CanonicaliseHost() with the latest routine from 2.7d, offered
by upstream. This stops bad IPv6 format IP addresses in URLs from
causing problems (memory overwriting, potential exploits).
This problem has been fixed in version 2.5c-10.4 for the old stable
distribution (potato), in version 2.7a-1.2 for the current stable
distribution (woody) and in version 2.7d-1 for the unstable
We recommend that you upgrade your wwwoffle packages.
Solution : http://www.debian.org/security/2002/dsa-144
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.