Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2003:106: fileutils/coreutils Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the fileutils/coreutils package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2003:106 (fileutils/coreutils).
A memory starvation denial of service vulnerability in the ls program was
discovered by Georgi Guninski. It is possible to allocate a huge amount of
memory by specifying certain command-line arguments. It is also possible to
exploit this remotely via programs that call ls such as wu-ftpd (although
wu-ftpd is no longer shipped with Mandrake Linux).
Likewise, a non-exploitable integer overflow problem was discovered in ls, which
can be used to crash ls by specifying certain command-line arguments. This can
also be triggered via remotely accessible services such as wu-ftpd.
The provided packages include a patched ls to fix these problems.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:106
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.