Nessus Plugin #16073

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[DSA620] DSA-620-1 perl

Family:
Debian Local Security Checks
Category:
infos
Copyright:
This script is (C) 2004 Michel Arboi
Summary:
DSA-620-1 perl
Version:
$Revision: 1.1 $
Cve_id:
CAN-2004-0452, CAN-2004-0976
Bugtraq_id:
-
Xrefs:
DSA:620
Description:

Several vulnerabilities have been discovered in Perl, the popular
scripting language. The Common Vulnerabilities and Exposures project
identifies the following problems:
Jeroen van Wolffelaar discovered that the rmtree() function in the
File::Path module removes directory trees in an insecure manner
which could lead to the removal of arbitrary files and directories
through a symlink attack.
Trustix developers discovered several insecure uses of temporary
files in many modules which allow a local attacker to overwrite
files via a symlink attack.
For the stable distribution (woody) these problems have been fixed in
version 5.6.1-8.8.
For the unstable distribution (sid) these problems have been fixed in
version 5.8.4-5.
We recommend that you upgrade your perl packages.


Solution : http://www.debian.org/security/2004/dsa-620
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.