Executive Summary
Summary | |
---|---|
Title | New maxdb-7.5.00 packages fix execution of arbitrary code |
Informations | |||
---|---|---|---|
Name | DSA-1190 | First vendor Publication | 2006-10-04 |
Vendor | Debian | Last vendor Modification | 2006-10-04 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Oliver Karow discovered that the WebDBM frontend of the MaxDB database performs insufficient sanitising of requests passed to it, which might lead to the execution of arbitrary code. For the stable distribution (sarge) this problem has been fixed in version 7.5.00.24-4. For the unstable distribution (sid) this problem will be fixed soon. We recommend that you upgrade your maxdb-7.5.00 package. |
Original Source
Url : http://www.debian.org/security/2006/dsa-1190 |
CPE : Common Platform Enumeration
SAINT Exploits
Description | Link |
---|---|
MySQL MaxDB WebDBM database name buffer overflow | More info here |
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 1190-1 (maxdb-7.5.00) File : nvt/deb_1190_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
28300 | SAP DB / MaxDB WebDBM Client Database Name Remote Overflow A buffer overflow exists in SAP DB/MaxDB. The WebDBM service fails to validate HTTP requests containing long database names resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | MaxDB WebDBM get buffer overflow RuleID : 13843 - Revision : 11 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-10-25 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1190.nasl - Type : ACT_GATHER_INFO |
2006-09-06 | Name : The remote web server is prone to a buffer overflow attack. File : webdbm_database_overflow.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:26:15 |
|