Title : Debian Security Update Fixes Multiple phpSysInfo Vulnerabilities VUPEN ID : VUPEN/ADV-2005-2424 CVE ID : CVE-2005-0870 - CVE-2005-3347 - CVE-2005-3348
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-11-15
Technical Description
Debian has released updated packages to correct multiple vulnerabilities identified in phpSysInfo. These flaws may be exploited by remote attackers to conduct directory traversal or cross site scripting attacks. For additional information, see : VUPEN/ADV-2005-2393 and VUPEN/ADV-2005-0570
Debian GNU/Linux old-stable (woody) - Upgrade to version 2.0-3woody3
Debian GNU/Linux stable (sarge) - Upgrade to version 2.3-4sarge1
Debian GNU/Linux unstable (sid) - A fix will be available soon References