Nessus Plugin #14567

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[GLSA-200408-11] race condition vulnerability

Family:
Gentoo Local Security Checks
Category:
infos
Copyright:
(C) 2004 Michel Arboi
Summary:
race condition vulnerability
Version:
$Revision: 1.1 $
Cve_id:
-
Bugtraq_id:
-
Xrefs:
GLSA:200408-11
Description:
The remote host is affected by the vulnerability described in GLSA-200408-11
( race condition vulnerability)


A race condition can occur in "nessus-adduser" if the user has
not configured their TMPDIR variable.

Impact

A malicious user could exploit this bug to escalate privileges to the
rights of the user running "nessus-adduser".

Workaround

There is no known workaround at this time. All users are encouraged to
upgrade to the latest available version of Nessus.

References:
http://secunia.com/advisories/12127/


Solution:
All Nessus users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=net-analyzer/nessus-2.0.12"
# emerge ">=net-analyzer/nessus-2.0.12"


Risk Factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.