Nessus Plugin #15030

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[DSA193] DSA-193-1 kdenetwork

Family:
Debian Local Security Checks
Category:
infos
Copyright:
This script is (C) 2004 Michel Arboi
Summary:
DSA-193-1 kdenetwork
Version:
$Revision: 1.4 $
Cve_id:
CAN-2002-1247
Bugtraq_id:
6157
Xrefs:
DSA:193
Description:

iDEFENSE reports a security vulnerability in the klisa package, that
provides a LAN information service similar to "Network Neighbourhood",
which was discovered by Texonet. It is possible for a local attacker
to exploit a buffer overflow condition in resLISa, a restricted
version of KLISa. The vulnerability exists in the parsing of the
LOGNAME environment variable, an overly long value will overwrite the
instruction pointer thereby allowing an attacker to seize control of
the executable.
This problem has been fixed in version 2.2.2-14.2 for the current stable
distribution (woody) and in version 2.2.2-14.3 for the unstable
distribution (sid). The old stable distribution (potato) is not
affected since it doesn't contain a kdenetwork package.
We recommend that you upgrade your klisa package immediately.


Solution : http://www.debian.org/security/2002/dsa-193
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.