Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2006:070: sash Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the sash package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2006:070 (sash).
Tavis Ormandy of the Gentoo Security Project discovered a vulnerability in zlib
where a certain data stream would cause zlib to corrupt a data structure,
resulting in the linked application to dump core (CVE-2005-2096). Markus
Oberhumber discovered additional ways that a specially-crafted compressed
stream could trigger an overflow. A possible hacker could create such a stream that
would cause a linked application to crash if opened by a user (CVE-2005-1849).
Both of these issues have previously been fixed in zlib, but sash links
statically against zlib and is thus also affected by these issues. New sash
packages are available that link against the updated zlib packages.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:070
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.