Ubuntu Security Notice USN-4609-1
Ubuntu Security Notice 4609-1 - Fabian Henneke discovered that GOsa incorrectly handled client cookies. An authenticated user could exploit this with a crafted cookie to perform file deletions in the context of the user account that runs the web server. It was discovered that GOsa incorrectly handled user access control. A remote attacker could use this issue to log into any account with a username containing the word "success". Various other issues were also addressed.
from Packet Storm https://ift.tt/3e5761Y
from Packet Storm https://ift.tt/3e5761Y
Comments
Post a Comment