|
Family: Debian Local Security Checks --> Category: infos
[DSA034] DSA-034-1 ePerl Vulnerability Scan
Vulnerability Scan Summary DSA-034-1 ePerl
Detailed Explanation for this Vulnerability Test
Fumitoshi Ukai and Denis Barbier have found several
potential buffer overflow bugs in our version of ePerl as distributed in all of
our distributions.
When eperl is installed setuid root, it can switch to the UID/GID of
the scripts owner. Although Debian doesn't ship the program setuid
root, this is a useful feature which people may have activated
locally. When the program is used as /usr/lib/cgi-bin/nph-eperl the
bugs could lead into a remote vulnerability as well.
Version 2.2.14-0.7potato2 fixes this
we recommend you upgrade your eperl
package immediately.
Solution : http://www.debian.org/security/2001/dsa-034
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|