~wgrant/ubuntu-cve-tracker/main

« back to all changes in this revision

Viewing changes to retired/CVE-2007-0159

  • Committer: Kees Cook
  • Date: 2008-09-19 21:55:36 UTC
  • Revision ID: kees.cook@canonical.com-20080919215536-xv2fttw2hoozmih4
update all Publication Dates

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
PublicDate: 2007-01-09
1
2
Candidate: CVE-2007-0159
2
3
References:
3
4
 http://www.ubuntu.com/usn/usn-412-1
4
5
Description:
 
6
 Directory traversal vulnerability in the GeoIP_update_database_general
 
7
 function in libGeoIP/GeoIPUpdate.c in GeoIP 1.4.0 allows remote malicious
 
8
 update servers (possibly only update.maxmind.com) to overwrite arbitrary
 
9
 files via a .. (dot dot) in the database filename, which is returned by a
 
10
 request to app/update_getfilename.
5
11
Ubuntu-Description:
6
12
Notes:
7
13
Bugs: