SuSE 10 Security Update : YaST2 (ZYPP Patch Number 4623)

This script is Copyright (C) 2007-2012 Tenable Network Security, Inc.


Synopsis :

The remote SuSE 10 host is missing a security-related patch.

Description :

This update fixes a security bug in yast2-core that allowed local
attackers to provide malicious yast2 modules to yast2 that are
executed with root privileges. To trigger this vulnerability root has
to execute yast2 in an untrusted directory (i.e. /tmp). Thanks to
Stefan Nordhausen for reporting this to us.

Solution :

Apply ZYPP patch number 4623.

Risk factor :

High

Family: SuSE Local Security Checks

Nessus Plugin ID: 29613 ()

Bugtraq ID:

CVE ID:

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now