Package: maxdb-7.5.00
Severity: grave
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for maxdb-7.5.00.

CVE-2008-0244[0]:
| SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to
| execute arbitrary commands via "&&" and other shell metacharacters in
| exec_sdbinfo and other unspecified commands, which are executed when
| MaxDB invokes cons.exe.

Please check if this also works with the version we ship, I 
have no maxdb installation to test.

If you fix this vulnerability please also include the CVE id
in your changelog entry.

For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0244

Kind regards
Nico

-- 
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpq6bzKT3j3S.pgp
Description: PGP signature

Reply via email to