Nessus Plugin #15030
Plugin Index
Note: This file has been created from a
downloaded version of the Nessus Plugins
from
http://www.nessus.org/.
Therefore, the information here can be outdated.
[DSA193] DSA-193-1 kdenetwork
- Family:
- Debian Local Security Checks
- Category:
- infos
- Copyright:
- This script is (C) 2004 Michel Arboi
- Summary:
- DSA-193-1 kdenetwork
- Version:
- $Revision: 1.4 $
- Cve_id:
- CAN-2002-1247
- Bugtraq_id:
- 6157
- Xrefs:
- DSA:193
- Description:
iDEFENSE reports a security vulnerability in the klisa package, that
provides a LAN information service similar to "Network Neighbourhood",
which was discovered by Texonet. It is possible for a local attacker
to exploit a buffer overflow condition in resLISa, a restricted
version of KLISa. The vulnerability exists in the parsing of the
LOGNAME environment variable, an overly long value will overwrite the
instruction pointer thereby allowing an attacker to seize control of
the executable.
This problem has been fixed in version 2.2.2-14.2 for the current stable
distribution (woody) and in version 2.2.2-14.3 for the unstable
distribution (sid). The old stable distribution (potato) is not
affected since it doesn't contain a kdenetwork package.
We recommend that you upgrade your klisa package immediately.
Solution : http://www.debian.org/security/2002/dsa-193
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.