Apache / PHP 5.x Remote Code Execution Exploit
Posted: 06 Nov 2013, 12:57
I just found that my b3 was vulnerable at this exploit:
http://www.exploit-db.com/exploits/29290/
It appears to have been announced only a few days ago, but it is already widespread, so I think all the bubba users with external access to their system could be at risk
the php5 package is in excito's repositories so even if someone plugs the vulnerability at debian.org, it will not appear as an upgrade to bubba users...
thanks and best regards
giovanni
http://www.exploit-db.com/exploits/29290/
It appears to have been announced only a few days ago, but it is already widespread, so I think all the bubba users with external access to their system could be at risk
the php5 package is in excito's repositories so even if someone plugs the vulnerability at debian.org, it will not appear as an upgrade to bubba users...
thanks and best regards
giovanni