Allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.

Bug #421865 reported by Dave Walker
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
destar (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Binary package hint: destar

An unauthenticated remote attackers can add arbitrary users via a direct request to config/add/CfgOptUser. As demonstrated in the exploit code:
http://www.milw0rm.com/exploits/5298

CVE References

visibility: private → public
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for using Ubuntu and taking the time to report a bug. This package is in universe and is community supported. If you are able, perhaps you could prepare debdiffs to fix this by following https://wiki.ubuntu.com/SecurityUpdateProcedures.

Changed in destar (Ubuntu):
status: New → Confirmed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.