Bug#622897: webalizer: remote exploit

2011-04-18 Thread Moritz Mühlenhoff
On Fri, Apr 15, 2011 at 12:29:42PM -0400, Jim Salter wrote: Package: webalizer Version: 2.01.10-32.4 Severity: critical Tags: security Justification: root security hole A server I admin running Debian Lenny with the current version of webalizer installed was exploited through

Bug#622897: webalizer: remote exploit

2011-04-15 Thread Jim Salter
Package: webalizer Version: 2.01.10-32.4 Severity: critical Tags: security Justification: root security hole A server I admin running Debian Lenny with the current version of webalizer installed was exploited through webalizer. Once the attackers had a shell, they used an unknown, presumably