Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.51101
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2004:041
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory RHSA-2004:041.

Slocate is a security-enhanced version of locate, designed to find files on
a system via a central database.

Patrik Hornik discovered a vulnerability in Slocate versions up to and
including 2.7 where a carefully crafted database could overflow a
heap-based buffer. A local user could exploit this vulnerability to gain
slocate group privileges and then read the entire slocate database. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CVE-2003-0848 to this issue.

Users of Slocate should upgrade to these erratum packages, which contain
Slocate version 2.7 with the addition of a patch from Kevin Lindsay that
causes slocate to drop privileges before reading a user-supplied database.

For Red Hat Enterprise Linux 2.1 these packages also fix a buffer overflow
that affected unpatched versions of Slocate prior to 2.7. This
vulnerability could also allow a local user to gain slocate group
privileges. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2003-0056 to this issue.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2004-041.html

Risk factor : High

CVSS Score:
7.2

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2003-0848
Bugtraq: 20031006 SA-20031006 slocate vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=106546447321274&w=2
Bugtraq: 20031011 SA-20031006 slocate buffer overflow - exploitation proof (Google Search)
http://marc.info/?l=bugtraq&m=106589631819348&w=2
Debian Security Information: DSA-428 (Google Search)
http://www.debian.org/security/2004/dsa-428
http://www.redhat.com/archives/fedora-announce-list/2004-January/msg00009.html
http://www.mandriva.com/security/advisories?name=MDKSA-2004:004
http://www.ebitech.sk/patrik/SA/SA-20031006-A.txt
http://www.ebitech.sk/patrik/SA/SA-20031006.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11033
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A821
RedHat Security Advisories: RHSA-2004:040
http://rhn.redhat.com/errata/RHSA-2004-040.html
RedHat Security Advisories: RHSA-2004:041
SCO Security Bulletin: CSSA-2004-001.0
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2004-001.0/CSSA-2004-001.0.txt
http://secunia.com/advisories/10670
http://secunia.com/advisories/10683
http://secunia.com/advisories/10686
http://secunia.com/advisories/10698
http://secunia.com/advisories/10702
http://secunia.com/advisories/10720
http://secunia.com/advisories/10722
http://secunia.com/advisories/9962/
SGI Security Advisory: 20040201-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc
SGI Security Advisory: 20040202-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
http://www.trustix.org/errata/misc/2004/TSL-2004-0005-slocate.asc.txt
Common Vulnerability Exposure (CVE) ID: CVE-2003-0056
Bugtraq: 20030124 [USG- SA- 2003.001] USG Security Advisory (slocate) (Google Search)
http://marc.info/?l=bugtraq&m=104342864418213&w=2
Bugtraq: 20030125 Re: [USG- SA- 2003.001] USG Security Advisory (slocate) (Google Search)
http://marc.info/?l=bugtraq&m=104348607205691&w=2
Bugtraq: 20030202 GLSA: slocate (Google Search)
http://marc.info/?l=bugtraq&m=104428624705363&w=2
Caldera Security Advisory: CSSA-2003-009.0
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-009.0.txt
Conectiva Linux advisory: CLA-2003:643
http://www.net-security.org/advisory.php?id=2010
Debian Security Information: DSA-252 (Google Search)
http://www.debian.org/security/2003/dsa-252
http://www.mandriva.com/security/advisories?name=MDKSA-2003:015
http://www.usg.org.uk/advisories/2003.001.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11369
http://rhn.redhat.com/errata/RHSA-2004-041.html
http://secunia.com/advisories/7947
http://secunia.com/advisories/7982
http://secunia.com/advisories/8007
http://secunia.com/advisories/8118/
http://secunia.com/advisories/8236
http://secunia.com/advisories/8749
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.