| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.50505 |
| Kategorie: | Ubuntu Local Security Checks |
| Titel: | Ubuntu 4.10 USN-69-1 (evolution) |
| Zusammenfassung: | Ubuntu 4.10 USN-69-1 (evolution) |
| Beschreibung: | The remote host is missing an update to evolution announced via advisory USN-69-1. Max Vozeler discovered an integer overflow in camel-lock-helper. An user-supplied length value was not validated, so that a value of -1 caused a buffer allocation of 0 bytes this buffer was then filled by an arbitrary amount of user-supplied data. A local attacker or a malicious POP3 server could exploit this to execute arbitrary code with root privileges (because camel-lock-helper is installed as setuid root). The following packages are affected: evolution Solution: The problem can be corrected by upgrading the affected package to version 2.0.2-0ubuntu2.1. In general, a standard system upgrade is sufficient to effect the necessary changes. http://lists.ubuntu.com/archives/ubuntu-security-announce/2005-January/000071.html Risk factor : High |
| Querverweis: |
BugTraq ID: 12354 Common Vulnerability Exposure (CVE) ID: CVE-2005-0102 Conectiva Linux advisory: CLA-2005:925 http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000925 Debian Security Information: DSA-673 (Google Search) http://www.debian.org/security/2005/dsa-673 http://security.gentoo.org/glsa/glsa-200501-35.xml http://www.mandriva.com/security/advisories?name=MDKSA-2005:024 http://www.redhat.com/support/errata/RHSA-2005-238.html http://www.redhat.com/support/errata/RHSA-2005-397.html http://www.ubuntulinux.org/support/documentation/usn/usn-69-1 http://www.securityfocus.com/bid/12354 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9616 http://securitytracker.com/id?1012981 http://secunia.com/advisories/13830 XForce ISS Database: evolution-camellockhelper-bo(19031) http://xforce.iss.net/xforce/xfdb/19031 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|