Scientific Linux Security Update : nss_db on SL5.x i386/x86_64

This script is Copyright (C) 2012 Tenable Network Security, Inc.


Synopsis :

The remote Scientific Linux host is missing a security update.

Description :

It was discovered that nss_db did not specify a path to the directory
to be used as the database environment for the Berkeley Database
library, causing it to use the current working directory as the
default. This could possibly allow a local attacker to obtain
sensitive information. (CVE-2010-0826)

See also :

http://www.nessus.org/u?4f3b031b

Solution :

Update the affected nss_db package.

Risk factor :

Low / CVSS Base Score : 1.9
(CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N)

Family: Scientific Linux Local Security Checks

Nessus Plugin ID: 60780 ()

Bugtraq ID:

CVE ID: CVE-2010-0826