| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.63167 |
| Category: | FreeBSD Local Security Checks |
| Title: | FreeBSD Ports: verlihub |
| Summary: | FreeBSD Ports: verlihub |
| Description: | The remote host is missing an update to the system as announced in the referenced advisory. The following package is affected: verlihub CVE-2008-5705 The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier, when user triggers are enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in an argument. CVE-2008-5706 The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/trigger.tmp temporary file. Solution: Update your system with the appropriate patches or software upgrades. http://milw0rm.com/exploits/7183 http://www.vuxml.org/freebsd/58997463-e012-11dd-a765-0030843d3802.html |
| Cross-Ref: |
BugTraq ID: 32889 BugTraq ID: 32420 Common Vulnerability Exposure (CVE) ID: CVE-2008-5705 http://www.milw0rm.com/exploits/7183 http://openwall.com/lists/oss-security/2008/12/17/16 http://bugs.debian.org/506530 http://www.securityfocus.com/bid/32420 http://securityreason.com/securityalert/4800 XForce ISS Database: verlihub-trigger-command-execution(46801) http://xforce.iss.net/xforce/xfdb/46801 Common Vulnerability Exposure (CVE) ID: CVE-2008-5706 http://www.securityfocus.com/bid/32889 |
| Copyright | Copyright (c) 2009 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|