Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.59483
Category:Fedora Local Security Checks
Title:Fedora Core 6 FEDORA-2007-256 (gnucash)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to gnucash
announced via advisory FEDORA-2007-256.

GnuCash is a personal finance manager. A check-book like register GUI
allows you to enter and track bank accounts, stocks, income and even
currency trades. The interface is designed to be simple and easy to
use, but is backed with double-entry accounting principles to ensure
balanced books.

Update Information:

This updates GnuCash to version 2.0.5, the latest upstream
release.

Major changes in this release include

o Fix some strings not being translated.
o Use guiles native sort and record.
o Adjust how payment dialog resizes.
o Don't abort when F::Q fails to return a quote.
o Change Russian Ruble from RUR to RUB.
o Fix security problem with tmp filesystem and symlink
attack. (CVE-2007-0007)
o Add French and Canadian French translation updates.
o Do not crash on delete_event in new user dialog.
o Add sanity checks when accessing GncPluginPage.
o Make new windows the same size as the active one.
o The New Turkish Lira changed from TRL to TRY in 2005.

Thanks to Sami Farin for uncovering the /tmp file issue.

* Mon Feb 19 2007 Bill Nottingham - 2.0.5-1
- update to 2.0.5
- fixes: CVE-2007-0007

Solution: Apply the appropriate updates.

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/


This update can be installed with the 'yum' update program. Use 'yum update
package-name' at the command line. For more information, refer to 'Managing
Software with yum,' available at http://fedora.redhat.com/docs/yum/.


http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2007-256

Risk factor : Medium

CVSS Score:
3.6

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-0007
BugTraq ID: 22610
http://www.securityfocus.com/bid/22610
http://fedoranews.org/cms/node/2725
http://www.mandriva.com/security/advisories?name=MDKSA-2007:046
http://secunia.com/advisories/24225
http://secunia.com/advisories/24226
http://secunia.com/advisories/24317
http://www.vupen.com/english/advisories/2007/0653
XForce ISS Database: gnucash-symlink(32558)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32558
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.