Nessus Plugin #18009
Plugin Index
Note: This file has been created from a
downloaded version of the Nessus Plugins
from
http://www.nessus.org/.
Therefore, the information here can be outdated.
[DSA704] DSA-704-1 remstats
- Family:
- Debian Local Security Checks
- Category:
- infos
- Copyright:
- This script is (C) 2005 Michel Arboi
- Summary:
- DSA-704-1 remstats
- Version:
- $Revision: 1.2 $
- Cve_id:
- CAN-2005-0387, CAN-2005-0388
- Bugtraq_id:
- -
- Xrefs:
- DSA:704
- Description:
Jens Steube discovered several vulnerabilities in remstats, the remote
statistics system. The Common Vulnerabilities and Exposures project
identifies the following problems:
When processing uptime data on the unix-server a temporary file is
opened in an insecure fashion which could be used for a symlink
attack to create or overwrite arbitrary files with the permissions
of the remstats user.
The remoteping service can be exploited to execute arbitrary
commands due to missing input sanitising.
For the stable distribution (woody) these problems have been fixed in
version 1.00a4-8woody1.
For the unstable distribution (sid) these problems have been fixed in
version 1.0.13a-5.
We recommend that you upgrade your remstats packages.
Solution : http://www.debian.org/security/2005/dsa-704
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.