| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.61919 |
| Category: | FreeBSD Local Security Checks |
| Title: | FreeBSD Ports: syslog-ng2 |
| Summary: | FreeBSD Ports: syslog-ng2 |
| Description: | The remote host is missing an update to the system as announced in the referenced advisory. The following package is affected: syslog-ng2 CVE-2008-5110 syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. Solution: Update your system with the appropriate patches or software upgrades. http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505791 http://www.openwall.com/lists/oss-security/2008/11/17/3 http://www.vuxml.org/freebsd/75f2382e-b586-11dd-95f9-00e0815b8da8.html |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-5110 http://www.openwall.com/lists/oss-security/2008/11/17/3 http://security.gentoo.org/glsa/glsa-200907-10.xml HPdes Security Advisory: HPSBMA02554 http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083 HPdes Security Advisory: SSRT100018 http://secunia.com/advisories/35748 http://secunia.com/advisories/40551 http://www.vupen.com/english/advisories/2010/1796 |
| Copyright | Copyright (c) 2008 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|