This script is Copyright (C) 2004-2014 Tenable Network Security, Inc.
The remote Red Hat host is missing a security update.
Updated packages for sharutils which fix potential privilege
escalation using the uudecode utility are available.
The sharutils package contains a set of tools for encoding and
decoding packages of files in binary or text format.
The uudecode utility creates an output file without checking to see if
it was about to write to a symlink or a pipe. If a user uses uudecode
to extract data into open shared directories, such as /tmp, this
vulnerability could be used by a local attacker to overwrite files or
lead to privilege escalation.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2002-0178 to this issue.
Users are advised to upgrade to these errata sharutils packages which
contain a version of uudecode that has been patched to check for an
existing pipe or symlink output file.
See also :
Update the affected sharutils package.
Risk factor :
High / CVSS Base Score : 7.2
Family: Red Hat Local Security Checks
Nessus Plugin ID: 12398 ()
CVE ID: CVE-2002-0178
Upgrade to Nessus Professional today!
Start your free Nessus Cloud trial now!
Begin Free Trial
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.