Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:060: ksymoops Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the ksymoops package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:060 (ksymoops).
Geoffrey Lee discovered a problem with the ksymoops-gznm script distributed with
Mandrakelinux. The script fails to do proper checking when copying a file to the
/tmp directory. Because of this, a local attacker can setup a symlink to point
to a file that they do not have permission to remove. The problem is difficult
to exploit because someone with root rights needs to run ksymoops on a
particular module for which a symlink for the same filename already exists.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:060
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.