![]() |
Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | ||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.50726 |
Categoría: | Mandrake Local Security Checks |
Título: | Mandrake Security Advisory MDKSA-2003:068 (gzip) |
Resumen: | NOSUMMARY |
Descripción: | Description: The remote host is missing an update to gzip announced via advisory MDKSA-2003:068. A vulnerability exists in znew, a script included with gzip, that would create temporary files without taking precautions to avoid a symlink attack. Patches have been applied to make use of mktemp to generate unique filenames, and properly make use of noclobber in the script. Likewise, a fix for gzexe which had been applied previously was incomplete. It has been fixed to make full use of mktemp everywhere a temporary file is created. The znew problem was initially reported by Michal Zalewski and was again reported more recently to Debian by Paul Szabo. Affected versions: 8.2, 9.0, 9.1, Corporate Server 2.1, Multi Network Firewall 8.2 Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2003:068 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1332 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0367 http://marc.theaimsgroup.com/?l=bugtraq&m=88998519803911&w=2 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=193375 Risk factor : Medium CVSS Score: 2.1 |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-1999-1332 BugTraq ID: 7845 http://www.securityfocus.com/bid/7845 Bugtraq: 19980128 GZEXE - the big problem (Google Search) http://marc.info/?l=bugtraq&m=88603844115233&w=2 Debian Security Information: DSA-308 (Google Search) http://www.debian.org/security/2003/dsa-308 http://www.osvdb.org/3812 http://www.iss.net/security_center/static/7241.php Common Vulnerability Exposure (CVE) ID: CVE-2003-0367 BugTraq ID: 7872 http://www.securityfocus.com/bid/7872 http://www.mandriva.com/security/advisories?name=MDKSA-2003:068 TurboLinux Advisory: TLSA-2003-38 http://www.turbolinux.com/security/TLSA-2003-38.txt |
Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |