|
Family: Ubuntu Local Security Checks --> Category: infos
USN165-1 : heartbeat vulnerability Vulnerability Scan
Vulnerability Scan Summary heartbeat vulnerability
Detailed Explanation for this Vulnerability Test
Synopsis :
These remote packages are missing security patches :
- heartbeat
- heartbeat-dev
- ldirectord
- libpils-dev
- libpils0
- libstonith-dev
- libstonith0
- stonith
Description :
Eric Romang discovered that heartbeat created temporary files in an
insecure manner. This could allow a symlink attack to create or
overwrite arbitrary files with root rights as soon as heartbeat is
started.
Solution :
Upgrade to :
- heartbeat-1.2.3-3ubuntu1.1 (Ubuntu 5.04)
- heartbeat-dev-1.2.3-3ubuntu1.1 (Ubuntu 5.04)
- ldirectord-1.2.3-3ubuntu1.1 (Ubuntu 5.04)
- libpils-dev-1.2.3-3ubuntu1.1 (Ubuntu 5.04)
- libpils0-1.2.3-3ubuntu1.1 (Ubuntu 5.04)
- libstonith-dev-1.2.3-3ubuntu1.1 (Ubuntu 5.04)
- libstonith0-1.2.3-3ubuntu1.1 (Ubuntu 5.04)
- stonith-1.2.3-3ubuntu1.1 (Ubuntu 5.04)
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|