Mandrake Linux Security Advisory : ksymoops (MDKSA-2004:060)

This script is Copyright (C) 2004-2013 Tenable Network Security, Inc.

Synopsis :

The remote Mandrake Linux host is missing a security update.

Description :

Geoffrey Lee discovered a problem with the ksymoops-gznm script
distributed with Mandrakelinux. The script fails to do proper checking
when copying a file to the /tmp directory. Because of this, a local
attacker can setup a symlink to point to a file that they do not have
permission to remove. The problem is difficult to exploit because
someone with root privileges needs to run ksymoops on a particular
module for which a symlink for the same filename already exists.

Solution :

Update the affected ksymoops package.

Risk factor :

Medium / CVSS Base Score : 4.6

Family: Mandriva Local Security Checks

Nessus Plugin ID: 14159 (mandrake_MDKSA-2004-060.nasl)

Bugtraq ID:

CVE ID: CVE-2004-0581

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now