Title : Debian Security Update Fixes Slash Input Validation Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2475 CVE ID : CVE-2008-2231 - CVE-2008-2553
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-03
Technical Description
Multiple vulnerabilities have been identified in Debian, which could be exploited by remote attackers to inject arbitrary SQL queries and scripting code. These issues are caused by input validation errors in Slash, which could be exploited to conduct cross site scripting and SQL injection attacks.
Debian GNU/Linux etch - Upgrade to slash version 2.2.6-8etch1
Debian GNU/Linux sid - The slash package is currently uninstallable and will be removed soon References
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.