Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.56483
Kategorie:Mandrake Local Security Checks
Titel:Mandrake Security Advisory MDKSA-2006:027 (gzip)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing an update to gzip
announced via advisory MDKSA-2006:027.

Zgrep in gzip before 1.3.5 does not properly sanitize arguments, which
allows local users to execute arbitrary commands via filenames that are
injected into a sed script.

This was previously corrected in MDKSA-2005:092, however the fix was
incomplete. These updated packages provide a more comprehensive fix
to the problem.

Affected: 10.1, 10.2, 2006.0, Corporate 2.1, Corporate 3.0,
Multi Network Firewall 2.0


Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2006:027

Risk factor : Medium

CVSS Score:
4.6

Querverweis: BugTraq ID: 13582
Common Vulnerability Exposure (CVE) ID: CVE-2005-0758
1013928
http://securitytracker.com/id?1013928
13582
http://www.securityfocus.com/bid/13582
16371
http://www.osvdb.org/16371
18100
http://secunia.com/advisories/18100
19183
http://secunia.com/advisories/19183
20060301-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc
22033
http://secunia.com/advisories/22033
25159
http://www.securityfocus.com/bid/25159
26235
http://secunia.com/advisories/26235
ADV-2007-2732
http://www.vupen.com/english/advisories/2007/2732
APPLE-SA-2007-07-31
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
FLSA:158801
http://www.fedoralegacy.org/updates/FC2/2005-11-14-FLSA_2005_158801__Updated_bzip2_packages_fix_security_issues.html
GLSA-200505-05
http://www.gentoo.org/security/en/glsa/glsa-200505-05.xml
MDKSA-2006:026
http://www.mandriva.com/security/advisories?name=MDKSA-2006:026
MDKSA-2006:027
http://www.mandriva.com/security/advisories?name=MDKSA-2006:027
OpenPKG-SA-2007.002
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.002.html
RHSA-2005:357
http://rhn.redhat.com/errata/RHSA-2005-357.html
RHSA-2005:474
http://www.redhat.com/support/errata/RHSA-2005-474.html
SCOSA-2005.58
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.58/SCOSA-2005.58.txt
SSA:2006-262
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.555852
USN-158-1
http://www.ubuntu.com/usn/usn-158-1
gzip-zgrep-file-installation(20539)
https://exchange.xforce.ibmcloud.com/vulnerabilities/20539
http://bugs.gentoo.org/show_bug.cgi?id=90626
http://docs.info.apple.com/article.html?artnum=306172
oval:org.mitre.oval:def:1081
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1081
oval:org.mitre.oval:def:1107
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1107
oval:org.mitre.oval:def:9797
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9797
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.