Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51492
Category:Conectiva Local Security Checks
Title:Conectiva Security Advisory CLA-2002:448
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory CLA-2002:448.

LibGTop (from the Gnome project) is a library that fetches system
related information such as CPU Load, Memory Usage and running
processes. It includes a daemon (libgtop_daemon) which can be used to
monitor processes remotely.

There are two libgtop_daemon vulnerabilities addressed by this
advisory:

The first one[1] was found by the Laboratory intexxia and is related
to a format string vulnerability in the libgtop_daemon logging
mechanisms. The second[2] was found later[3] by Flavio Veloso when
investigating the first and is a buffer overflow in the same part of
the code.

By exploiting any of the vulnerabilities an attacker would be able to
execute arbitrary code with the privileges of the user libgtop_daemon
is running as.

Notice that libgtop_daemon is not invoked by default anywhere in
Conectiva Linux, even if you're running Gnome as your desktop.


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://www.securityfocus.com/archive/1/242542
http://www.securityfocus.com/bid/3594
http://www.securityfocus.com/archive/1/242922
http://www.securityspace.com/smysecure/catid.html?in=CLA-2002:448
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002002

Risk factor : High

CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.