Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51627
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2005:032 (cpio)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to cpio
announced via advisory MDKSA-2005:032.

A vulnerability in cpio was discovered where cpio would create world-
writeable files when used in -o/--create mode and giving an output
file (with -O). This would allow any user to modify the created cpio
archive. The updated packages have been patched so that cpio now
respects the current umask setting of the user.

Affected versions: 10.0, 10.1, 9.2, Corporate 3.0,
Corporate Server 2.1


Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2005:032
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1572

Risk factor : Medium

CVSS Score:
2.1

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-1999-1572
Bugtraq: 20050204 [USN-75-1] cpio vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=110763404701519&w=2
Debian Security Information: DSA-664 (Google Search)
http://www.debian.org/security/2005/dsa-664
http://www.mandriva.com/security/advisories?name=MDKSA-2005:032
http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10888
http://www.redhat.com/support/errata/RHSA-2005-073.html
http://www.redhat.com/support/errata/RHSA-2005-080.html
http://www.redhat.com/support/errata/RHSA-2005-806.html
http://secunia.com/advisories/14357
http://secunia.com/advisories/17063
http://secunia.com/advisories/17532
http://www.trustix.org/errata/2005/0003/
XForce ISS Database: cpio-o-archive-insecure-permissions(19167)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19167
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.