|
|
|
|
|
|
|
| |
[DSA622] DSA-622-1 htmlheadline |
|
| This script is (C) 2005-2010 Tenable Network Security, Inc. |
|
|
| Family | Debian Local Security Checks |
| Nessus Plugin ID | 16087 (debian_DSA-622.nasl) |
| Bugtraq ID |
|
| CVE ID | CVE-2004-1181
|
|
| Description: |
Synopsis :
The remote host is missing the DSA-622 security update
Description :
Javier Fernández-Sanguino Peña from the Debian Security Audit Project
has discovered multiple insecure uses
of temporary files that could lead to overwriting arbitrary files via
a symlink attack.
For the stable distribution (woody) these problems have been fixed in
version 21.8-3.
See also :
http://www.debian.org/security/2005/dsa-622
Solution :
The Debian project recommends that you upgrade your htmlheadline package.
Risk factor :
Medium / CVSS Base Score : 4.6
(CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P)
|
|
|
|
|
|