From 3f37e5016662a202cf9d5581aae5315894a77966 Mon Sep 17 00:00:00 2001 From: crees Date: Sat, 13 Aug 2011 15:02:29 +0000 Subject: Document dtc security issues PR: ports/159736 Submitted by: Ansgar Burchardt --- security/vuxml/vuln.xml | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) (limited to 'security/vuxml') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 0d1d06aa3b89..67b995d5a543 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,42 @@ Note: Please add new entries to the beginning of this file. --> + + dtc -- multiple vulnerabilities + + + dtc + 0.32.9 + + + + +

Ansgar Burchardt reports:

+
+

Ansgar Burchardt discovered several vulnerabilities in DTC, a + web control panel for admin and accounting hosting services: + The bw_per_moth.php graph contains an SQL injection vulnerability; + Insufficient checks in bw_per_month.php can lead to bandwidth + usage information disclosure; After a registration, passwords are + sent in cleartext email messages and Authenticated users could + delete accounts using an obsolete interface which was incorrectly + included in the package.

+
+ +
+ + CVE-2011-0434 + CVE-2011-0435 + CVE-2011-0436 + CVE-2011-0437 + http://www.debian.org/security/2011/dsa-2179 + + + 2011-03-02 + 2011-08-13 + +
+ libXfont -- possible local privilege escalation -- cgit