bug-gnats
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Serious security flaw in Gnatsweb


From: Yngve Svendsen
Subject: Serious security flaw in Gnatsweb
Date: Tue, 26 Jun 2001 22:39:55 +0200

Gnatsweb versions 2.7 beta, 2.8.0 and 2.8.1 have a serious security hole, potentially allowing an attacker to read or execute files on the Gnatsweb server machine. A security advisory, with fixes, are available from http://sources.redhat.com/gnats/gnatsweb/advisory-jun-26-2001.html

I urge people running the affected Gnatsweb versions to apply the fixes immediately, or download version 2.8.2 of Gnatsweb which incorporates the fix.

People running Gnatsweb 3.95 for GNATS 4 from CVS, checked out prior to June 26 2001 12:15 PDT should check out the newest version, which incorporates the fix.

Yngve Svendsen
Gnatsweb maintainer




reply via email to

[Prev in Thread] Current Thread [Next in Thread]