Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.55852
Category:Fedora Local Security Checks
Title:Fedora Legacy Security Advisory FLSA-2005:152848
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory FLSA-2005:152848.

Flaws in the catchsegv and glibcbug scripts were discovered. A local
user could utilize these flaws to overwrite files via a symlink attack
on temporary files. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2004-0968 and CVE-2004-1382
to these issues.

It was discovered that the use of LD_DEBUG and LD_SHOW_AUXV were not
restricted for a setuid program. A local user could utilize this flaw to
gain information, such as the list of symbols used by the program. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2004-1453 to this issue.

Users of glibc are advised to upgrade to these erratum packages that
remove the unecessary glibcbug script and contain backported patches to
correct these other issues.

Affected platforms:
Redhat 7.3
Redhat 9
Fedora Core 1
Fedora Core 2

Solution:
http://www.securityspace.com/smysecure/catid.html?in=FLSA-2005:152848

Risk factor : Medium

CVSS Score:
2.1

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0968
BugTraq ID: 11286
http://www.securityfocus.com/bid/11286
Debian Security Information: DSA-636 (Google Search)
http://www.debian.org/security/2005/dsa-636
http://security.gentoo.org/glsa/glsa-200410-19.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9523
http://www.redhat.com/support/errata/RHSA-2004-586.html
http://www.redhat.com/support/errata/RHSA-2005-261.html
http://www.trustix.org/errata/2004/0050
https://www.ubuntu.com/usn/usn-4-1/
XForce ISS Database: script-temporary-file-overwrite(17583)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17583
Common Vulnerability Exposure (CVE) ID: CVE-2004-1382
Bugtraq: 20041028 [USN-4-1] Standard C library script vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=109899903129801&w=2
http://www.mandriva.com/security/advisories?name=MDKSA-2004:159
Common Vulnerability Exposure (CVE) ID: CVE-2004-1453
BugTraq ID: 10963
http://www.securityfocus.com/bid/10963
http://www.gentoo.org/security/en/glsa/glsa-200408-16.xml
http://bugs.gentoo.org/show_bug.cgi?id=59526
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10762
http://www.redhat.com/support/errata/RHSA-2005-256.html
http://secunia.com/advisories/12306
XForce ISS Database: glibc-suid-info-disclosure(17006)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17006
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.