oval:org.mitre.oval:def:7732

Definition Id: oval:org.mitre.oval:def:7732
 
Oval ID: oval:org.mitre.oval:def:7732
Title: DSA-1473 scponly -- design flaw
Description: Joachim Breitner discovered that Subversion support in scponly is inherently insecure, allowing execution of arbitrary commands. Further investigation showed that rsync and Unison support suffer from similar issues. This set of issues has been assigned CVE-2007-6350. In addition, it was discovered that it was possible to invoke scp with certain options that may lead to the execution of arbitrary commands (CVE-2007-6415). This update removes Subversion, rsync and Unison support from the scponly package, and prevents scp from being invoked with the dangerous options.
Family: unix Class: patch
Reference(s): DSA-1473
CVE-2007-6350
CVE-2007-6415
Version: 3
Platform(s): Debian GNU/Linux 4.0
Debian GNU/Linux 3.1
Product(s): scponly
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:6461
 
Oval ID: oval:org.mitre.oval:def:6461
Title: Debian GNU/Linux 4.0 is installed.
Description: Debian GNU/Linux 4.0 (etch) is installed
Family: unix Class: inventory
Reference(s): cpe:/o:debian:debian_gnu/linux:4.0
Version: 9
Platform(s): Debian GNU/Linux 4.0
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:7732
Definition Id: oval:org.mitre.oval:def:7692
 
Oval ID: oval:org.mitre.oval:def:7692
Title: Debian GNU/Linux 3.1 is installed
Description: Debian GNU/Linux 3.1 (sarge) is installed
Family: unix Class: inventory
Reference(s): cpe:/o:debian:debian_gnu/linux:3.1
Version: 7
Platform(s): Debian GNU/Linux 3.1
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:7732