Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-14955

Опубликовано: 02 окт. 2017
Источник: debian

Описание

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
check-mkfixed1.2.8p26-1package
check-mknot-affectedwheezypackage

Примечания

  • http://mathias-kettner.com/check_mk_werks.php?edition_id=raw&branch=1.2.8

  • https://mathias-kettner.de/check_mk_werks.php?werk_id=5208&HTML=yes

  • http://git.mathias-kettner.de/git/?p=check_mk.git;a=commitdiff;h=a4a2cc1f30ff6032899ca80eed29fa26b8898c54

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

CVSS3: 6.5
redhat
больше 8 лет назад

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

CVSS3: 5.9
nvd
больше 8 лет назад

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

CVSS3: 5.9
github
больше 3 лет назад

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.