FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

pound remotely exploitable vulnerability

Affected packages
pound < 1.6

Details

VuXML ID fb521119-9bc4-11d8-9366-0020ed76ef5a
Discovery 2003-12-01
Entry 2004-05-02

An unknown remotely exploitable vulnerability was disclosed. Robert Segall writes:

a security vulnerability was brought to my attention (many thanks to Akira Higuchi). Everyone running any previous version should upgrade to 1.6 immediately - the vulnerability may allow a remote exploit. No exploits are currently known and none have been observed in the wild till now. The danger is minimised if you run Pound in a root jail and/or you run Pound as non-root user.

References

Message http://www.apsis.ch/pound/pound_list/archive/2003/2003-12/1070234315000