| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.50449 |
| Category: | Ubuntu Local Security Checks |
| Title: | Ubuntu 4.10 USN-13-1 (groff utility) |
| Summary: | Ubuntu 4.10 USN-13-1 (groff utility) |
| Description: | The remote host is missing an update to groff utility announced via advisory USN-13-1. Recently, Trustix Secure Linux discovered a vulnerability in the groff package. The utility 'groffer' created a temporary directory in an insecure way, which allowed exploitation of a race condition to create or overwrite files with the privileges of the user invoking the program. The following packages are affected: groff Solution: The problem can be corrected by upgrading the affected package to version 1.18.1.1-1ubuntu0.1. In general, a standard system upgrade is sufficient to effect the necessary changes. http://lists.ubuntu.com/archives/ubuntu-security-announce/2004-November/000015.html Risk factor : Medium |
| Cross-Ref: |
BugTraq ID: 11287 Common Vulnerability Exposure (CVE) ID: CVE-2004-0969 http://www.gentoo.org/security/en/glsa/glsa-200411-15.xml http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:038 http://www.trustix.org/errata/2004/0050 http://www.securityfocus.com/bid/11287 http://secunia.com/advisories/18764 XForce ISS Database: script-temporary-file-overwrite(17583) http://xforce.iss.net/xforce/xfdb/17583 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|