Family: Debian Local Security Checks --> Category: infos
[DSA193] DSA-193-1 kdenetwork Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
iDEFENSE reports a security vulnerability in the klisa package, that
provides a LAN information service similar to "Network Neighbourhood",
which was discovered by Texonet. It is possible for a local attacker
to exploit a buffer overflow condition in resLISa, a restricted
version of KLISa. The vulnerability exists in the parsing of the
LOGNAME environment variable, an overly long value will overwrite the
instruction pointer thereby allowing a possible hacker to seize control of
This problem has been fixed in version 2.2.2-14.2 for the current stable
distribution (woody) and in version 2.2.2-14.3 for the unstable
distribution (sid). The old stable distribution (potato) is not
affected since it doesn't contain a kdenetwork package.
We recommend that you upgrade your klisa package immediately.
Solution : http://www.debian.org/security/2002/dsa-193
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.