Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.53939
Categoría:Slackware Local Security Checks
Título:Slackware Advisory SSA:2004-110-01 utempter security update
Resumen:The remote host is missing an update as announced;via advisory SSA:2004-110-01.
Descripción:Summary:
The remote host is missing an update as announced
via advisory SSA:2004-110-01.

Vulnerability Insight:
New utempter packages are available for Slackware 9.1 and -current to
fix a security issue. (Slackware 9.1 was the first version of Slackware
to use the libutempter library, and earlier versions of Slackware are
not affected by this issue)

The utempter package provides a utility and shared library that
allows terminal applications such as xterm and screen to update
/var/run/utmp and /var/log/wtmp without requiring root privileges.
Steve Grubb has identified an issue with utempter-0.5.2 where
under certain circumstances an attacker could cause it to
overwrite files through a symlink. This has been addressed by
upgrading the utempter package to use Dmitry V. Levin's new
implementation of libutempter that does not have this bug.

Solution:
Upgrade to the new package(s).

CVSS Score:
2.1

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:N

Referencia Cruzada: BugTraq ID: 10178
Common Vulnerability Exposure (CVE) ID: CVE-2004-0233
http://www.securityfocus.com/bid/10178
http://security.gentoo.org/glsa/glsa-200405-05.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:031
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10115
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A979
http://www.redhat.com/support/errata/RHSA-2004-174.html
http://www.redhat.com/support/errata/RHSA-2004-175.html
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.404389
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000752.1-1
XForce ISS Database: utemper-symlink(15904)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15904
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.