![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.50689 |
Category: | Mandrake Local Security Checks |
Title: | Mandrake Security Advisory MDKSA-2003:026 (shadow-utils) |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing an update to shadow-utils announced via advisory MDKSA-2003:026. The shadow-utils package contains the tool useradd, which is used to create or update new user information. When useradd creates an account, it would create it with improper permissions instead of having it owned by the group mail, it would be owned by the user's primary group. If this is a shared group (ie. users), then all members of the shared group would be able to obtain access to the mail spools of other members of the same group. A patch to useradd has been applied to correct this problem. Affected versions: 8.1, 8.2, 9.0, Multi Network Firewall 8.2 Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2003:026 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1509 Risk factor : Medium CVSS Score: 3.6 |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2002-1509 http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:026 http://www.redhat.com/support/errata/RHSA-2003-057.html http://www.redhat.com/support/errata/RHSA-2003-058.html |
Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |