Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2001:074: WindowMaker Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the WindowMaker package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2001:074 (WindowMaker).
A buffer overflow exists in the WindowMaker window manager's window title
handling code, as discovered by Alban Hertroys. Many programs, such as web
browsers, set the window title to something obtained from the network, such as
the title of the currently-viewed web page. As such, this buffer overflow could
be exploited remotely. WindowMaker versions above and including 0.65.1 are fixed
these packages have been patched to correct the problem.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2001:074
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.