diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index e509e4839034..e0d2eea553c3 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -350,12 +350,15 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + CAN-2004-0796 + 10957 http://marc.theaimsgroup.com/?l=spamassassin-announce&m=109168121628767 http://search.cpan.org/src/JMASON/Mail-SpamAssassin-2.64/Changes 2004-08-04 2004-08-23 + 2004-08-28 @@ -520,6 +523,8 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + CAN-2004-0794 + 10967 http://cvsweb.netbsd.org/bsdweb.cgi/src/libexec/ftpd/ftpd.c#rev1.158 ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2004-009.txt.asc http://lists.netsys.com/pipermail/full-disclosure/2004-August/025418.html @@ -527,6 +532,7 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 2004-08-17 2004-08-17 + 2004-08-28 @@ -4598,6 +4604,10 @@ misc.c: + CAN-2004-0627 + CAN-2004-0628 + 184030 + 645326 http://www.nextgenss.com/advisories/mysql-authbypass.txt http://dev.mysql.com/doc/mysql/en/News-4.1.3.html http://secunia.com/advisories/12020 @@ -4608,7 +4618,7 @@ misc.c: 2004-07-01 2004-07-05 - 2004-08-12 + 2004-08-28 @@ -4976,22 +4986,28 @@ misc.c: -

Andres Salomon noticed a problem in the CGI session - management of Ruby, an object-oriented scripting language. - CGI::Session's FileStore (and presumably PStore) - implementations store session information insecurely. - They simply create files, ignoring permission issues. - This can lead an attacker who has also shell access to the - webserver to take over a session.

+

According to a Debian Security Advisory:

+
+

Andres Salomon noticed a problem in the CGI session + management of Ruby, an object-oriented scripting language. + CGI::Session's FileStore (and presumably PStore [...]) + implementations store session information insecurely. + They simply create files, ignoring permission issues. + This can lead an attacker who has also shell access to the + webserver to take over a session.

+
+ CAN-2004-0755 + http://xforce.iss.net/xforce/xfdb/16996 http://www.debian.org/security/2004/dsa-537 http://marc.theaimsgroup.com/?l=bugtraq&m=109267579822250&w=2 2004-08-16 2004-08-16 + 2004-08-28