Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50985
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2003:087
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2003:087.

The file command is used to identify a particular file according to
the type of data contained by the file.

The file utility before version 3.41 contains a buffer overflow
vulnerability in the ELF parsing routines. This vulnerability may
allow an attacker to create a carefully crafted binary which can cause
arbitrary code to run if a victim runs the file command against that
binary.

On some distributions it may also be possible to trigger this file command
vulnerability by encouraging the victim to use the
less command on an exploited file name so that it will be processed by the
lesspipe.sh script.

All users are advised to update to these erratum packages which
contain a backported patch to correct this vulnerability.

Red Hat would like to thank iDefense for disclosing this issue and
zen-parse for discussion of some of the implications.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2003-087.html
http://www.idefense.com/advisory/03.04.03.txt

Risk factor : Medium

CVSS Score:
4.6

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2003-0102
BugTraq ID: 7008
http://www.securityfocus.com/bid/7008
Bugtraq: 20030304 [OpenPKG-SA-2003.017] OpenPKG Security Advisory (file) (Google Search)
Bugtraq: 20030304 iDEFENSE Security Advisory 03.04.03: Locally Exploitable Buffer Overflow in file(1) (Google Search)
http://marc.info/?l=bugtraq&m=104680706201721&w=2
CERT/CC vulnerability note: VU#611865
http://www.kb.cert.org/vuls/id/611865
Debian Security Information: DSA-260 (Google Search)
http://www.debian.org/security/2003/dsa-260
Immunix Linux Advisory: IMNX-2003-7+-012-01
http://lwn.net/Alerts/34908/
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:030
http://www.idefense.com/advisory/03.04.03.txt
NETBSD Security Advisory: NetBSD-SA2003-003
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-003.txt.asc
http://www.redhat.com/support/errata/RHSA-2003-086.html
http://www.redhat.com/support/errata/RHSA-2003-087.html
SuSE Security Announcement: SuSE-SA:2003:017 (Google Search)
http://www.novell.com/linux/security/advisories/2003_017_file.html
XForce ISS Database: file-afctr-read-bo(11469)
https://exchange.xforce.ibmcloud.com/vulnerabilities/11469
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.