[Pkg-erlang-devel] Bug#603748: CVE-2010-4181

Moritz Muehlenhoff jmm at debian.org
Tue Nov 16 22:06:47 UTC 2010


Package: yaws
Severity: grave
Tags: security

The following vulnerability has been reported in YAWS:

| Directory traversal vulnerability in Yaws 1.89 allows remote attackers
| to read arbitrary files via ..\ (dot dot backslash) and other
| sequences.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4181

This seems unfixed/unnoticed upstream AFAICT. Please get in touch with
upstream.

Cheers,
        Moritz

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.32-5-686 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15 at euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages yaws depends on:
ii  adduser                       3.112+nmu1 add and remove users and groups
pn  erlang-abi-11.b.3             <none>     (no description available)
pn  erlang-nox                    <none>     (no description available)
ii  libc6                         2.11.2-6   Embedded GNU C Library: Shared lib
ii  libpam0g                      1.1.1-6    Pluggable Authentication Modules l
ii  openssl                       0.9.8o-2   Secure Socket Layer (SSL) binary a

yaws recommends no packages.

Versions of packages yaws suggests:
pn  erlang-dev                    <none>     (no description available)
pn  yaws-chat                     <none>     (no description available)
pn  yaws-mail                     <none>     (no description available)
pn  yaws-wiki                     <none>     (no description available)
pn  yaws-yapp                     <none>     (no description available)





More information about the Pkg-erlang-devel mailing list