![]() |
Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | ||
Test Kennung: | 1.3.6.1.4.1.25623.1.0.51492 |
Kategorie: | Conectiva Local Security Checks |
Titel: | Conectiva Security Advisory CLA-2002:448 |
Zusammenfassung: | NOSUMMARY |
Beschreibung: | Description: The remote host is missing updates announced in advisory CLA-2002:448. LibGTop (from the Gnome project) is a library that fetches system related information such as CPU Load, Memory Usage and running processes. It includes a daemon (libgtop_daemon) which can be used to monitor processes remotely. There are two libgtop_daemon vulnerabilities addressed by this advisory: The first one[1] was found by the Laboratory intexxia and is related to a format string vulnerability in the libgtop_daemon logging mechanisms. The second[2] was found later[3] by Flavio Veloso when investigating the first and is a buffer overflow in the same part of the code. By exploiting any of the vulnerabilities an attacker would be able to execute arbitrary code with the privileges of the user libgtop_daemon is running as. Notice that libgtop_daemon is not invoked by default anywhere in Conectiva Linux, even if you're running Gnome as your desktop. Solution: The apt tool can be used to perform RPM package upgrades by running 'apt-get update' followed by 'apt-get upgrade' http://www.securityfocus.com/archive/1/242542 http://www.securityfocus.com/bid/3594 http://www.securityfocus.com/archive/1/242922 http://www.securityspace.com/smysecure/catid.html?in=CLA-2002:448 http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002002 Risk factor : High |
Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |