The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitrary code via crafted CGI arguments.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-3405-1 smokeping security update
EUVD EUVD EUVD-2015-0870 The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitrary code via crafted CGI arguments.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published:

Updated: 2024-08-06T04:26:11.052Z

Reserved: 2015-01-07T00:00:00

Link: CVE-2015-0859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-12-03T20:59:00.083

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-0859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.