Mandrake Linux Security Advisory : fileutils (MDKSA-2002:031)

low Nessus Plugin ID 13937

Synopsis

The remote Mandrake Linux host is missing a security update.

Description

Wojciech Purczynski reported a race condition in some utilities in the GNU fileutils package that may cause root to delete the entire filesystem. This only affects version 4.1 stable and 4.1.6 development versions, and the authors have fixed this in the latest development version.

Solution

Update the affected fileutils package.

See Also

https://isec.pl/en/vulnerabilities/0002.txt

http://mail.gnu.org/pipermail/bug-fileutils/2002-March/002440.html

Plugin Details

Severity: Low

ID: 13937

File Name: mandrake_MDKSA-2002-031.nasl

Version: 1.19

Type: local

Published: 7/31/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Low

Base Score: 1.2

Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:fileutils, cpe:/o:mandrakesoft:mandrake_linux:8.1, cpe:/o:mandrakesoft:mandrake_linux:8.2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 5/16/2002

Reference Information

CVE: CVE-2002-0435

MDKSA: 2002:031