[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2259-1 fex -- authentication bypass

ID: oval:org.secpod.oval:def:600568Date: (C)2011-06-14   (M)2022-10-10
Class: PATCHFamily: unix




It was discovered that fex, a web service for transferring very large, files, is not properly validating authentication IDs. While the service properly validates existing authentication IDs, an attacker who is not specifying any authentication ID at all, can bypass the authentication procedure. The oldstable distribution does not include fex.

Platform:
Debian 6.0
Product:
fex
Reference:
DSA-2259-1
CVE-2011-1409
CVE    1
CVE-2011-1409
CPE    3
cpe:/a:ulli_horlacher:fex:20100208
cpe:/o:debian:debian_linux:6.0
cpe:/a:ulli_horlacher:fex

© SecPod Technologies