| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.52178 |
| Category: | FreeBSD Local Security Checks |
| Title: | FreeBSD Ports: unace |
| Summary: | FreeBSD Ports: unace |
| Description: | The remote host is missing an update to the system as announced in the referenced advisory. The following package is affected: unace CVE-2005-0160 Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain 'Ready for next volume' messages. CVE-2005-0161 Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames. Solution: Update your system with the appropriate patches or software upgrades. |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2005-0160 http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html SuSE Security Announcement: SUSE-SR:2005:016 (Google Search) http://www.novell.com/linux/security/advisories/2005_16_sr.html CERT/CC vulnerability note: VU#215006 http://www.kb.cert.org/vuls/id/215006 BugTraq ID: 12630 http://www.securityfocus.com/bid/12630 http://secunia.com/advisories/14359 Common Vulnerability Exposure (CVE) ID: CVE-2005-0161 BugTraq ID: 12628 http://www.securityfocus.com/bid/12628 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|