Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:057-1: tripwire Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the tripwire package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:057-1 (tripwire).
Paul Herman discovered a format string vulnerability in tripwire that could
allow a local user to execute arbitrary code with the rights of the user running
tripwire (typically root). This vulnerability only exists when tripwire is
generating an email report.
The packages previously released for Mandrakelinux 9.2 would segfault when doing
a check due to compilation problems. The updated packages correct the problem.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:057-1
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.