Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.50642
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2004:004 (slocate)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to slocate
announced via advisory MDKSA-2004:004.

A vulnerability was discovered by Patrik Hornik in slocate versions up
to and including 2.7 where a carefully crafted database could overflow
a heap-based buffer. This could be exploited by a local user to gain
privileges of the 'slocate' group. The updated packages contain a
patch from Kevin Lindsay that causes slocate to drop privileges before
reading a user-supplied database.

Affected versions: 9.1, 9.2, Corporate Server 2.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2004:004
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0848

Risk factor : Medium

CVSS Score:
4.6

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2003-0848
Bugtraq: 20031006 SA-20031006 slocate vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=106546447321274&w=2
Bugtraq: 20031011 SA-20031006 slocate buffer overflow - exploitation proof (Google Search)
http://marc.info/?l=bugtraq&m=106589631819348&w=2
Debian Security Information: DSA-428 (Google Search)
http://www.debian.org/security/2004/dsa-428
http://www.redhat.com/archives/fedora-announce-list/2004-January/msg00009.html
http://www.mandriva.com/security/advisories?name=MDKSA-2004:004
http://www.ebitech.sk/patrik/SA/SA-20031006-A.txt
http://www.ebitech.sk/patrik/SA/SA-20031006.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11033
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A821
RedHat Security Advisories: RHSA-2004:040
http://rhn.redhat.com/errata/RHSA-2004-040.html
http://www.redhat.com/support/errata/RHSA-2004-041.html
SCO Security Bulletin: CSSA-2004-001.0
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2004-001.0/CSSA-2004-001.0.txt
http://secunia.com/advisories/10670
http://secunia.com/advisories/10683
http://secunia.com/advisories/10686
http://secunia.com/advisories/10698
http://secunia.com/advisories/10702
http://secunia.com/advisories/10720
http://secunia.com/advisories/10722
http://secunia.com/advisories/9962/
SGI Security Advisory: 20040201-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc
SGI Security Advisory: 20040202-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
http://www.trustix.org/errata/misc/2004/TSL-2004-0005-slocate.asc.txt
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.