| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.54406 |
| Category: | Ubuntu Local Security Checks |
| Title: | Ubuntu USN-150-1 (kdelibs) |
| Summary: | Ubuntu USN-150-1 (kdelibs) |
| Description: | The remote host is missing an update to kdelibs announced via advisory USN-150-1. ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.04 (Hoary Hedgehog) The following packages are affected: kdelibs4 The problem can be corrected by upgrading the affected package to version 4:3.4.0-0ubuntu3.3. In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Kate and Kwrite create a backup file before saving a modified file. These backup files were created with default permissions, even if the original file had more strict permissions set, so that other local users could possibly read the backup file even if they are not permitted to read the original file. Solution: http://www.securityspace.com/smysecure/catid.html?in=USN-150-1 Risk factor : Medium |
| Cross-Ref: |
BugTraq ID: 14297 Common Vulnerability Exposure (CVE) ID: CVE-2005-1920 Bugtraq: 20050718 [KDE Security Advisory]: Kate backup file permission leak (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=112171434023679&w=2 Debian Security Information: DSA-804 (Google Search) http://www.debian.org/security/2005/dsa-804 http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded http://security.gentoo.org/glsa/glsa-200611-21.xml http://www.redhat.com/support/errata/RHSA-2005-612.html SuSE Security Announcement: SUSE-SR:2005:018 (Google Search) http://www.novell.com/linux/security/advisories/2005_18_sr.html http://www.securityfocus.com/bid/14297 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9434 http://securitytracker.com/id?1014512 http://secunia.com/advisories/16099 http://secunia.com/advisories/23099 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|