Nessus Plugin #15139

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[DSA302] DSA-302-1 fuzz

Family:
Debian Local Security Checks
Category:
infos
Copyright:
This script is (C) 2004 Michel Arboi
Summary:
DSA-302-1 fuzz
Version:
$Revision: 1.4 $
Cve_id:
CAN-2003-0261
Bugtraq_id:
7521
Xrefs:
DSA:302
Description:

Joey Hess discovered that fuzz, a software stress-testing tool,
creates a temporary file without taking appropriate security
precautions. This bug could allow an attacker to gain the privileges
of the user invoking fuzz, excluding root (fuzz does not allow itself
to be invoked as root).
For the stable distribution (woody) this problem has been fixed in
version 0.6-6woody1.
The old stable distribution (potato) does not contain a fuzz package.
For the unstable distribution (sid) this problem will be fixed soon.
We recommend that you update your fuzz package.


Solution : http://www.debian.org/security/2003/dsa-302
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.