Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.52282
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: cscope
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to the system
as announced in the referenced advisory.

The following package is affected: cscope

CVE-2004-0996
main.c in cscope 15-4 and 15-5 creates temporary files with
predictable filenames, which allows local users to overwrite arbitrary
files via a symlink attack.

Solution:
Update your system with the appropriate patches or
software upgrades.

http://sourceforge.net/tracker/index.php?func=detail&aid=1062807&group_id=4664&atid=104664
http://marc.theaimsgroup.com/?l=bugtraq&m=110133485519690
http://marc.theaimsgroup.com/?l=bugtraq&m=110072752707293
http://www.vuxml.org/freebsd/a7bfd423-484f-11d9-a9e7-0001020eed82.html

CVSS Score:
2.1

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:N

Querverweis: BugTraq ID: 11697
Common Vulnerability Exposure (CVE) ID: CVE-2004-0996
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
http://www.securityfocus.com/bid/11697
BugTraq ID: 25159
http://www.securityfocus.com/bid/25159
Bugtraq: 20041117 RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch. (Google Search)
http://www.securityfocus.com/archive/1/381443
Bugtraq: 20041118 Re: RX171104 Cscope v15.5 and minors - symlink vulnerability - advisory, exploit and patch. (Google Search)
http://www.securityfocus.com/archive/1/381506
http://www.securityfocus.com/archive/1/381611
Bugtraq: 20041124 STG Security Advisory: [SSA-20041122-09] cscope insecure temp file creation vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=110133485519690&w=2
Debian Security Information: DSA-610 (Google Search)
http://www.debian.org/security/2004/dsa-610
http://www.gentoo.org/security/en/glsa/glsa-200412-11.xml
http://secunia.com/advisories/26235
http://www.vupen.com/english/advisories/2007/2732
XForce ISS Database: cscope-tmp-race-condition(18125)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18125
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.