Vulnerabilities > CVE-2001-1035 - Unspecified vulnerability in Slrn Development Team Slrn

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
slrn-development-team
nessus

Summary

Binary decoding feature of slrn 0.9 and earlier allows remote attackers to execute commands via shell scripts that are inserted into a news post.

Vulnerable Configurations

Part Description Count
Application
Slrn_Development_Team
1

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-078.NASL
descriptionByrial Jensen found a nasty problem in slrn (a threaded news reader). The notice on slrn-announce describes it as follows : When trying to decode binaries, the built-in code executes any shell scripts the article might contain, apparently assuming they would be some kind of self-extracting archive.
last seen2020-06-01
modified2020-06-02
plugin id14915
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/14915
titleDebian DSA-078-1 : slrn - remote command invocation