Nessus Plugin #15754

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[GLSA-200411-26] GIMPS, SETI@home, ChessBrain: Insecure installation

Family:
Gentoo Local Security Checks
Category:
infos
Copyright:
(C) 2004 Michel Arboi
Summary:
GIMPS, SETI@home, ChessBrain: Insecure installation
Version:
$Revision: 1.1 $
Cve_id:
-
Bugtraq_id:
11698, 11699, 11700
Xrefs:
GLSA:200411-26
Description:
The remote host is affected by the vulnerability described in GLSA-200411-26
(GIMPS, SETI@home, ChessBrain: Insecure installation)


GIMPS, SETI@home and ChessBrain ebuilds install user-owned binaries and
init scripts which are executed with root privileges.

Impact

This could lead to a local privilege escalation or root compromise.

Workaround

There is no known workaround at this time.


Solution:
All GIMPS users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-sci/gimps-23.9-r1"
All SETI@home users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-sci/setiathome-3.03-r2"
All ChessBrain users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-sci/chessbrain-20407-r1"


Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.