Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.60761
Category:Fedora Local Security Checks
Title:Fedora Core 8 FEDORA-2008-2981 (comix)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to comix
announced via advisory FEDORA-2008-2981.

Several security flaws are reported against comix 3.6.4. One issue is that
comix uses os.popen() to execute external commands without handling filenames
properly. This may allow malicios users to execute arbitrary commands by opening
some files with crafted names. This issue is now identified as CVE-2008-1568.
Another issue is that comix creates a directory under /tmp with the name easily
predictable by any users. This will cause DOS attach for multiuser system.
This new package will fix these issues.

ChangeLog:

* Thu Apr 3 2008 Mamoru Tasaka - 3.6.4-6
- Second patch for bug 430635
Use tempfile.mkdtemp() for multiple user race condition
* Wed Apr 2 2008 Mamoru Tasaka - 3.6.4-4
- First patch for bug 430635
Replace os.popen() with subprocess.Popen() to handle hostile filename
properly (CVE-2008-1568)

References:

[ 1 ] Bug #430635 - comix: multiple issues (CVE-2008-1568)
https://bugzilla.redhat.com/show_bug.cgi?id=430635

Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update comix' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-2981

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-1568
BugTraq ID: 28547
http://www.securityfocus.com/bid/28547
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00171.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00183.html
http://security.gentoo.org/glsa/glsa-200804-29.xml
http://secunia.com/advisories/29621
http://secunia.com/advisories/29731
http://secunia.com/advisories/29956
XForce ISS Database: comix-filename-command-execution(41554)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41554
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.