Title : Debian Security Update Fixes Slash Input Validation Vulnerabilities VUPEN ID : VUPEN/ADV-2008-2475 CVE ID : CVE-2008-2231 - CVE-2008-2553
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-09-03
Technical Description
Multiple vulnerabilities have been identified in Debian, which could be exploited by remote attackers to inject arbitrary SQL queries and scripting code. These issues are caused by input validation errors in Slash, which could be exploited to conduct cross site scripting and SQL injection attacks.
Debian GNU/Linux etch - Upgrade to slash version 2.2.6-8etch1
Debian GNU/Linux sid - The slash package is currently uninstallable and will be removed soon References