Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Debian Local Security Checks --> Category: infos

[DSA364] DSA-364-3 man-db Vulnerability Scan


Vulnerability Scan Summary
DSA-364-3 man-db

Detailed Explanation for this Vulnerability Test

man-db provides the standard man(1) command on Debian systems. During
configuration of this package, the administrator is asked whether
man(1) should run setuid to a dedicated user ("man") in order to
provide a shared cache of preformatted manual pages. The default is
for man(1) NOT to be setuid, and in this configuration no known
vulnerability exists. However, if the user explicitly requests setuid
operation, a local attacker could exploit either of the following bugs to
execute arbitrary code as the "man" user.
Again, these vulnerabilities do not affect the default configuration,
where man is not setuid.
For the current stable distribution (woody), these problems have been
fixed in version 2.3.20-18.woody.4.
For the unstable distribution (sid), these problems have been fixed in
version 2.4.1-13.
We recommend that you update your man-db package.


Solution : http://www.debian.org/security/2003/dsa-364
Threat Level: High

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.