|
Family: Ubuntu Local Security Checks --> Category: infos
USN5-1 : gettext vulnerabilities Vulnerability Scan
Vulnerability Scan Summary gettext vulnerabilities
Detailed Explanation for this Vulnerability Test
Synopsis :
These remote packages are missing security patches :
- gettext
- gettext-base
- gettext-doc
- gettext-el
Description :
Recently, Trustix Secure Linux discovered some vulnerabilities in the
gettext package. The programs "autopoint" and "gettextize" created
temporary files in an insecure way, which allowed a symlink attack to
create or overwrite arbitrary files with the rights of the user
invoking the program.
Solution :
Upgrade to :
- gettext-0.14.1-2ubuntu0.1 (Ubuntu 4.10)
- gettext-base-0.14.1-2ubuntu0.1 (Ubuntu 4.10)
- gettext-doc-0.14.1-2ubuntu0.1 (Ubuntu 4.10)
- gettext-el-0.14.1-2ubuntu0.1 (Ubuntu 4.10)
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|