Executive Summary
Summary | |
---|---|
Title | New gnump3d packages fix several vulnerabilities |
Informations | |||
---|---|---|---|
Name | DSA-877 | First vendor Publication | 2005-10-28 |
Vendor | Debian | Last vendor Modification | 2005-10-28 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Steve Kemp discovered two vulnerabilities in gnump3d, a streaming server for MP3 and OGG files. The Common Vulnerabilities and Exposures Project identifies the following problems: CVE-2005-3122 The 404 error page does not strip malicious javascript content from the resulting page, which would be executed in the victims browser. CVE-2005-3123 By using specially crafting URLs it is possible to read arbitary files to which the user of the streaming server has access to. The old stable distribution (woody) does not contain a gnump3d package. For the stable distribution (sarge) these problems have been fixed in version 2.9.3-1sarge2. For the unstable distribution (sid) these problems have been fixed in version 2.9.6-1. We recommend that you upgrade your gnump3d package. |
Original Source
Url : http://www.debian.org/security/2005/dsa-877 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200511-05 (gnump3d) File : nvt/glsa_200511_05.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 877-1 (gnump3d) File : nvt/deb_877_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
20723 | GNUMP3d Unspecified XSS |
20360 | GNUMP3d Server Traversal Arbitrary File Access GNUMP3d contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the program not properly sanitizing user input, specifically traversal style attacks (../../). |
20359 | GNUMP3d Error Page XSS GNUMP3d contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate URLs before returning them in a 404 error page. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-877.nasl - Type : ACT_GATHER_INFO |
2005-11-07 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200511-05.nasl - Type : ACT_GATHER_INFO |
2005-10-31 | Name : The remote streaming server is prone to directory traversal and cross- site s... File : gnump3d_296.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:34:35 |
|
2013-05-11 12:19:15 |
|