![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.60761 |
Category: | Fedora Local Security Checks |
Title: | Fedora Core 8 FEDORA-2008-2981 (comix) |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing an update to comix announced via advisory FEDORA-2008-2981. Several security flaws are reported against comix 3.6.4. One issue is that comix uses os.popen() to execute external commands without handling filenames properly. This may allow malicios users to execute arbitrary commands by opening some files with crafted names. This issue is now identified as CVE-2008-1568. Another issue is that comix creates a directory under /tmp with the name easily predictable by any users. This will cause DOS attach for multiuser system. This new package will fix these issues. ChangeLog: * Thu Apr 3 2008 Mamoru Tasaka - 3.6.4-6 - Second patch for bug 430635 Use tempfile.mkdtemp() for multiple user race condition * Wed Apr 2 2008 Mamoru Tasaka - 3.6.4-4 - First patch for bug 430635 Replace os.popen() with subprocess.Popen() to handle hostile filename properly (CVE-2008-1568) References: [ 1 ] Bug #430635 - comix: multiple issues (CVE-2008-1568) https://bugzilla.redhat.com/show_bug.cgi?id=430635 Solution: Apply the appropriate updates. This update can be installed with the yum update program. Use su -c 'yum update comix' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/. http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-2981 Risk factor : High CVSS Score: 7.5 |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-1568 BugTraq ID: 28547 http://www.securityfocus.com/bid/28547 https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00171.html https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00183.html http://security.gentoo.org/glsa/glsa-200804-29.xml http://secunia.com/advisories/29621 http://secunia.com/advisories/29731 http://secunia.com/advisories/29956 XForce ISS Database: comix-filename-command-execution(41554) https://exchange.xforce.ibmcloud.com/vulnerabilities/41554 |
Copyright | Copyright (c) 2008 E-Soft Inc. http://www.securityspace.com |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |