Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64039
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1806-1)
Summary:The remote host is missing an update for the Debian 'cscope' package(s) announced via the DSA-1806-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'cscope' package(s) announced via the DSA-1806-1 advisory.

Vulnerability Insight:
Matt Murphy discovered that cscope, a source code browsing tool, does not verify the length of file names sourced in include statements, which may potentially lead to the execution of arbitrary code through specially crafted source code files.

For the stable distribution (lenny), this problem has been fixed in version 15.6-6+lenny1.

Due to a technical limitation in the Debian archive management scripts the update for the old stable distribution (etch) cannot be released synchronously. It will be fixed in version 15.6-2+etch1 soon.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your cscope package.

Affected Software/OS:
'cscope' package(s) on Debian 4, Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-0148
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
BugTraq ID: 34805
http://www.securityfocus.com/bid/34805
Cert/CC Advisory: TA09-133A
http://www.us-cert.gov/cas/techalerts/TA09-133A.html
Debian Security Information: DSA-1806 (Google Search)
http://www.debian.org/security/2009/dsa-1806
http://security.gentoo.org/glsa/glsa-200905-02.xml
http://sourceforge.net/mailarchive/forum.php?thread_name=E1LsGx3-00015K-TN%40ddv4jf1.ch3.sourceforge.com&forum_name=cscope-cvs
http://www.openwall.com/lists/oss-security/2009/05/06/9
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9633
http://www.redhat.com/support/errata/RHSA-2009-1101.html
http://www.redhat.com/support/errata/RHSA-2009-1102.html
http://www.securitytracker.com/id?1022218
http://secunia.com/advisories/34978
http://secunia.com/advisories/35074
http://secunia.com/advisories/35213
http://secunia.com/advisories/35214
http://secunia.com/advisories/35462
http://www.vupen.com/english/advisories/2009/1238
http://www.vupen.com/english/advisories/2009/1297
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.