Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.55229
Kategorie:Mandrake Local Security Checks
Titel:Mandrake Security Advisory MDKSA-2005:160 (kdebase)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing an update to kdebase
announced via advisory MDKSA-2005:160.

Ilja van Sprundel from suresec.org notified the KDE security team about
a serious lock file handling error in kcheckpass that can, in some
configurations, be used to gain root access.

In order for an exploit to succeed, the directory /var/lock has to be
writeable for a user that is allowed to invoke kcheckpass.

The updated packages have been patched to correct this problem.

Affected versions: 10.1, 10.2, Corporate 3.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2005:160
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2494
http://www.kde.org/info/security/advisory-20050905-1.txt

Risk factor : High

CVSS Score:
7.2

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2005-2494
14736
http://www.securityfocus.com/bid/14736
16692
http://secunia.com/advisories/16692
18139
http://secunia.com/advisories/18139
20050905 [KDE Security Advisory] kcheckpass local root vulnerability
http://marc.info/?l=bugtraq&m=112603999215453&w=2
20050907 [ Suresec Advisories ] - Kcheckpass file creation vulnerability
http://marc.info/?l=bugtraq&m=112611555928169&w=2
21481
http://secunia.com/advisories/21481
DSA-815
http://www.debian.org/security/2005/dsa-815
MDKSA-2005:160
http://www.mandriva.com/security/advisories?name=MDKSA-2005:160
RHSA-2006:0582
http://www.redhat.com/support/errata/RHSA-2006-0582.html
USN-176-1
http://www.ubuntu.com/usn/usn-176-1
ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.2-kdebase-kcheckpass.diff
http://www.kde.org/info/security/advisory-20050905-1.txt
http://www.suresec.org/advisories/adv6.pdf
oval:org.mitre.oval:def:9388
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9388
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.