Family: Debian Local Security Checks --> Category: infos
[DSA836] DSA-836-1 cfengine2 Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
Javier Fernández-Sanguino Peña discovered insecure temporary file use
in cfengine2, a tool for configuring and maintaining networked
machines, that can be exploited by a symlink attack to overwrite
arbitrary files owned by the user executing cfengine, which is
The old stable distribution (woody) is not affected by this problem.
For the stable distribution (sarge) these problems have been fixed in
For the unstable distribution (sid) these problems will be fixed soon.
We recommend that you upgrade your cfengine2 package.
Solution : http://www.debian.org/security/2005/dsa-836
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.