![]() |
Startseite ▼ Bookkeeping
Online ▼ Sicherheits
Überprüfungs ▼
Verwaltetes
DNS ▼
Info
Bestellen/Erneuern
FAQ
AUP
Dynamic DNS Clients
Domaine konfigurieren Dyanmic DNS Update Password Netzwerk
Überwachung ▼
Enterprise
Erweiterte
Standard
Gratis Test
FAQ
Preis/Funktionszusammenfassung
Bestellen
Beispiele
Konfigurieren/Status Alarm Profile | ||
Test Kennung: | 1.3.6.1.4.1.25623.1.1.10.2014.0058 |
Kategorie: | Mageia Linux Local Security Checks |
Titel: | Mageia: Security Advisory (MGASA-2014-0058) |
Zusammenfassung: | The remote host is missing an update for the 'augeas' package(s) announced via the MGASA-2014-0058 advisory. |
Beschreibung: | Summary: The remote host is missing an update for the 'augeas' package(s) announced via the MGASA-2014-0058 advisory. Vulnerability Insight: Multiple flaws were found in the way Augeas handled configuration files when updating them. An application using Augeas to update configuration files in a directory that is writable to by a different user (for example, an application running as root that is updating files in a directory owned by a non-root service user) could have been tricked into overwriting arbitrary files or leaking information via a symbolic link or mount point attack (CVE-2012-0786, CVE-2012-0787). A flaw was found in the way Augeas handled certain umask settings when creating new configuration files. This flaw could result in configuration files being created as world writable, allowing unprivileged local users to modify their content (CVE-2013-6412). Affected Software/OS: 'augeas' package(s) on Mageia 3. Solution: Please install the updated package(s). CVSS Score: 4.6 CVSS Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P |
Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2012-0786 RedHat Security Advisories: RHSA-2013:1537 http://rhn.redhat.com/errata/RHSA-2013-1537.html http://secunia.com/advisories/55811 Common Vulnerability Exposure (CVE) ID: CVE-2012-0787 Common Vulnerability Exposure (CVE) ID: CVE-2013-6412 RHSA-2014:0044 http://rhn.redhat.com/errata/RHSA-2014-0044.html https://bugzilla.redhat.com/show_bug.cgi?id=1034261 https://github.com/hercules-team/augeas/commit/f5b4fc0c https://github.com/hercules-team/augeas/pull/58 |
Copyright | Copyright (C) 2022 Greenbone AG |
Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |