Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53786
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 023-1 (inn2)
Summary:The remote host is missing an update to inn2;announced via advisory DSA 023-1.
Description:Summary:
The remote host is missing an update to inn2
announced via advisory DSA 023-1.

Vulnerability Insight:
1. People at WireX have found several potential insecure uses of
temporary files in programs provided by INN2. Some of them only
lead to a vulnerability to symlink attacks if the temporary
directory was set to /tmp or /var/tmp, which is the case in many
installations, at least in Debian packages. An attacker could
overwrite any file owned by the news system administrator,
i.e. owned by news.news.

2. Michal Zalewski found an exploitable buffer overflow with regard
to cancel messages and their verification. This bug did only show
up if 'verifycancels' was enabled in inn.conf which is not the
default and has been disrecommended by upstream.

3. Andi Kleen found a bug in INN2 that makes innd crash for two byte
headers. There is a chance this can only be exploited with uucp.

We recommend you upgrade your inn2 packages immediately.

Solution:
Please install the updated package(s).

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2001-0361
BugTraq ID: 2344
http://www.securityfocus.com/bid/2344
Bugtraq: 20010207 [CORE SDI ADVISORY] SSH1 session key recovery vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=98158450021686&w=2
Computer Incident Advisory Center Bulletin: L-047
http://www.ciac.org/ciac/bulletins/l-047.shtml
Cisco Security Advisory: 20010627 Multiple SSH Vulnerabilities
Debian Security Information: DSA-023 (Google Search)
http://www.debian.org/security/2001/dsa-023
Debian Security Information: DSA-027 (Google Search)
http://www.debian.org/security/2001/dsa-027
Debian Security Information: DSA-086 (Google Search)
http://www.debian.org/security/2001/dsa-086
FreeBSD Security Advisory: FreeBSD-SA-01:24
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:24.ssh.asc
http://www.osvdb.org/2116
SuSE Security Announcement: SuSE-SA:2001:04 (Google Search)
http://www.novell.com/linux/security/advisories/adv004_ssh.html
XForce ISS Database: ssh-session-key-recovery(6082)
https://exchange.xforce.ibmcloud.com/vulnerabilities/6082
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.