![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.51492 |
Category: | Conectiva Local Security Checks |
Title: | Conectiva Security Advisory CLA-2002:448 |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing updates announced in advisory CLA-2002:448. LibGTop (from the Gnome project) is a library that fetches system related information such as CPU Load, Memory Usage and running processes. It includes a daemon (libgtop_daemon) which can be used to monitor processes remotely. There are two libgtop_daemon vulnerabilities addressed by this advisory: The first one[1] was found by the Laboratory intexxia and is related to a format string vulnerability in the libgtop_daemon logging mechanisms. The second[2] was found later[3] by Flavio Veloso when investigating the first and is a buffer overflow in the same part of the code. By exploiting any of the vulnerabilities an attacker would be able to execute arbitrary code with the privileges of the user libgtop_daemon is running as. Notice that libgtop_daemon is not invoked by default anywhere in Conectiva Linux, even if you're running Gnome as your desktop. Solution: The apt tool can be used to perform RPM package upgrades by running 'apt-get update' followed by 'apt-get upgrade' http://www.securityfocus.com/archive/1/242542 http://www.securityfocus.com/bid/3594 http://www.securityfocus.com/archive/1/242922 http://www.securityspace.com/smysecure/catid.html?in=CLA-2002:448 http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002002 Risk factor : High |
Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |