Mandrake Linux Security Advisory : expect (MDKSA-2001:087)

This script is Copyright (C) 2004-2013 Tenable Network Security, Inc.

Synopsis :

The remote Mandrake Linux host is missing a security update.

Description :

A packaging problem that can lead to a root compromise existed in the
expect package as provided in Mandrake Linux 8.1. expect would look
for libraries in the directory /home/snailtalk/tmp/tcltk-root/usr/lib
before any other and if such a user existed on the system, with rogue
libraries, if root were to execute expect, a compromise could occur.

Solution :

Update the affected expect package.

Risk factor :

High / CVSS Base Score : 7.2

Family: Mandriva Local Security Checks

Nessus Plugin ID: 13900 (mandrake_MDKSA-2001-087.nasl)

Bugtraq ID:

CVE ID: CVE-2001-0912

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now