Nessus Plugin #15686

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[DSA588] DSA-588-1 gzip

Family:
Debian Local Security Checks
Category:
infos
Copyright:
This script is (C) 2004 Michel Arboi
Summary:
DSA-588-1 gzip
Version:
$Revision: 1.1 $
Cve_id:
CAN-2004-0970
Bugtraq_id:
11288
Xrefs:
DSA:588
Description:

Trustix developers discovered insecure temporary file creation in
supplemental scripts in the gzip package which may allow local users
to overwrite files via a symlink attack.
For the stable distribution (woody) these problems have been fixed in
version 1.3.2-3woody3.
The unstable distribution (sid) is not affected by these problems.
We recommend that you upgrade your gzip package.


Solution : http://www.debian.org/security/2004/dsa-588
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.