| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.50709 |
| Kategorie: | Mandrake Local Security Checks |
| Titel: | Mandrake Security Advisory MDKSA-2003:047 (xfsdump) |
| Zusammenfassung: | Mandrake Security Advisory MDKSA-2003:047 (xfsdump) |
| Beschreibung: | The remote host is missing an update to xfsdump announced via advisory MDKSA-2003:047. A vulnerability was discovered in xfsdump by Ethan Benson related to filesystem quotas on the XFS filesystem. When xfsdump runs xfsdq to save the quota information into a file at the root of the filesystem being dumped, the file is created in an unsafe manner. A new option to xfsdq was added when fixing this vulnerability: '-f path'. This specifies an output file to use instead of the default output stream. If the file exists already, xfsdq will abort and if the file doesn't already exist, it will be created with more appropriate access permissions. Affected versions: 8.2, 9.0, 9.1, Corporate Server 2.1 Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2003:047 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0173 Risk factor : High |
| Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2003-0173 SGI Security Advisory: 20030404-01-P ftp://patches.sgi.com/support/free/security/advisories/20030404-01-P Debian Security Information: DSA-283 (Google Search) http://www.debian.org/security/2003/dsa-283 http://www.mandriva.com/security/advisories?name=MDKSA-2003:047 CERT/CC vulnerability note: VU#111673 http://www.kb.cert.org/vuls/id/111673 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|