Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.55357
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-815-1)
Summary:The remote host is missing an update for the Debian 'kdebase' package(s) announced via the DSA-815-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'kdebase' package(s) announced via the DSA-815-1 advisory.

Vulnerability Insight:
Ilja van Sprundel discovered a serious lock file handling error in kcheckpass that can, in some configurations, be used to gain root access.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in version 3.3.2-1sarge1.

For the unstable distribution (sid) this problem has been fixed in version 3.4.2-3.

We recommend that you upgrade your kdebase-bin package.

Affected Software/OS:
'kdebase' package(s) on Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-2494
14736
http://www.securityfocus.com/bid/14736
16692
http://secunia.com/advisories/16692
18139
http://secunia.com/advisories/18139
20050905 [KDE Security Advisory] kcheckpass local root vulnerability
http://marc.info/?l=bugtraq&m=112603999215453&w=2
20050907 [ Suresec Advisories ] - Kcheckpass file creation vulnerability
http://marc.info/?l=bugtraq&m=112611555928169&w=2
21481
http://secunia.com/advisories/21481
DSA-815
http://www.debian.org/security/2005/dsa-815
MDKSA-2005:160
http://www.mandriva.com/security/advisories?name=MDKSA-2005:160
RHSA-2006:0582
http://www.redhat.com/support/errata/RHSA-2006-0582.html
USN-176-1
http://www.ubuntu.com/usn/usn-176-1
ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.2-kdebase-kcheckpass.diff
http://www.kde.org/info/security/advisory-20050905-1.txt
http://www.suresec.org/advisories/adv6.pdf
oval:org.mitre.oval:def:9388
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9388
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.