Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.56794
Category:Slackware Local Security Checks
Title:Slackware: Security Advisory (SSA:2006-142-02)
Summary:The remote host is missing an update for the 'zoo' package(s) announced via the SSA:2006-142-02 advisory.
Description:Summary:
The remote host is missing an update for the 'zoo' package(s) announced via the SSA:2006-142-02 advisory.

Vulnerability Insight:
New bin packages are available for Slackware 10.2 and -current to
fix a security issue with the zoo archive program. A non-security-
related upgrade to the newest version of 'eject' was also done.


Here are the details from the Slackware 10.2 ChangeLog:
+--------------------------+
patches/packages/bin-10.2-i486-2_10.2.tgz:
Upgraded to eject-2.1.4 to fix problems with 2.6 kernels (bugfix).
Patched a security problem in zoo's fullpath() function that was reported by
Jean-Sebastien Guay-Leroux. At first this didn't seem like much as zoo is
old and hardly used, but there are virus scanning programs that scan zoo
archives. It is a possible problem on any system running zoo like this in
an automated way, and (of course) could also cause problems if a user were
to open a malicious zoo archive manually. (though I'd be pretty suspicious
if someone were to mail me anything using 'zoo' in 2006...)
(* Security fix *)
+--------------------------+

Affected Software/OS:
'zoo' package(s) on Slackware 10.2, Slackware current.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.