Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Mandrake Local Security Checks --> Category: infos

MDKSA-2002:047: util-linux Vulnerability Scan


Vulnerability Scan Summary
Check for the version of the util-linux package

Detailed Explanation for this Vulnerability Test

The remote host is missing the patch for the advisory MDKSA-2002:047 (util-linux).


Michal Zalewski found a vulnerability in the util-linux package with the chfn
utility. This utility allows users to modify some information in the /etc/passwd
file, and is installed setuid root. Using a carefully crafted attack sequence,
a possible hacker can exploit a complex file locking and modification race that would
allow them to make changes to the /etc/passwd file. To successfully exploit this
vulnerability and obtain privilege escalation, there is a need for some
administrator interaction, and the password file must over over 4kb in size
the
attacker's entry cannot be in the last 4kb of the file.


Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2002:047
Threat Level: High

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.