CVE-2015-0859

Publication date 3 December 2015

Last updated 24 July 2024


Ubuntu priority

The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitrary code via crafted CGI arguments.

Status

Package Ubuntu Release Status
smokeping 17.04 zesty
Not affected
16.10 yakkety
Not affected
16.04 LTS xenial
Not affected
15.10 wily Ignored end of life
15.04 vivid
Fixed 2.6.9-1+deb8u1build0.15.04.1
14.04 LTS trusty
Fixed 2.6.8-2+deb7u1ubuntu0.14.04.1
12.04 LTS precise Ignored end of life