| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.56255 |
| Category: | Ubuntu Local Security Checks |
| Title: | Ubuntu USN-247-1 (heimdal) |
| Summary: | Ubuntu USN-247-1 (heimdal) |
| Description: | The remote host is missing an update to heimdal announced via advisory USN-247-1. A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty Warthog) Ubuntu 5.04 (Hoary Hedgehog) Ubuntu 5.10 (Breezy Badger) The following packages are affected: heimdal-servers A privilege escalation flaw has been found in the heimdal rsh (remote shell) server. This allowed an authenticated attacker to overwrite arbitrary files and gain ownership of them. Please note that the heimdal-servers package is not officially supported in Ubuntu (it is in the 'universe' component of the archive). However, this affects you if you use a customized version built from the heimdal source package (which is supported). Solution: The problem can be corrected by upgrading the affected package to version 0.6.2-3ubuntu0.2 (for Ubuntu 4.10), 0.6.3-7ubuntu1.2 (for Ubuntu 5.04), or 0.6.3-11ubuntu1.1 (for Ubuntu 5.10). In general, a standard system upgrade is sufficient to effect the necessary changes. http://www.securityspace.com/smysecure/catid.html?in=USN-247-1 Risk factor : Medium |
| Cross-Ref: |
BugTraq ID: 16524 Common Vulnerability Exposure (CVE) ID: CVE-2006-0582 http://www.stacken.kth.se/lists/heimdal-discuss/2006-02/msg00028.html Debian Security Information: DSA-977 (Google Search) http://www.debian.org/security/2006/dsa-977 http://www.gentoo.org/security/en/glsa/glsa-200603-14.xml SuSE Security Announcement: SUSE-SA:2006:011 (Google Search) http://www.securityfocus.com/archive/1/archive/1/426043/100/0/threaded http://www.ubuntu.com/usn/usn-253-1 http://www.ubuntulinux.org/support/documentation/usn/usn-247-1 http://www.securityfocus.com/bid/16524 http://www.vupen.com/english/advisories/2006/0456 http://www.vupen.com/english/advisories/2006/0628 http://www.osvdb.org/22986 http://securitytracker.com/id?1015591 http://secunia.com/advisories/18733 http://secunia.com/advisories/18894 http://secunia.com/advisories/18806 http://secunia.com/advisories/19005 http://secunia.com/advisories/19302 XForce ISS Database: heimdal-rshd-privilege-elevation(24532) http://xforce.iss.net/xforce/xfdb/24532 |
| Copyright | Copyright (c) 2006 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|