Mandriva Linux Security Advisory : cifs-utils (MDVSA-2012:069)

low Nessus Plugin ID 59011

Synopsis

The remote Mandriva Linux host is missing a security update.

Description

A vulnerability has been found and corrected in cifs-utils :

A file existence dislosure flaw was found in the way mount.cifs tool of the Samba SMB/CIFS tools suite performed mount of a Linux CIFS (Common Internet File System) filesystem. A local user, able to mount a remote CIFS share / target to a local directory could use this flaw to confirm (non) existence of a file system object (file, directory or process descriptor) via error messages generated during the mount.cifs tool run (CVE-2012-1586).

The updated packages have been patched to correct this issue.

Solution

Update the affected cifs-utils package.

See Also

https://bugzilla.samba.org/show_bug.cgi?id=8821

Plugin Details

Severity: Low

ID: 59011

File Name: mandriva_MDVSA-2012-069.nasl

Version: 1.11

Type: local

Published: 5/7/2012

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.2

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:cifs-utils, cpe:/o:mandriva:linux:2010.1, cpe:/o:mandriva:linux:2011

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/4/2012

Reference Information

CVE: CVE-2012-1586

BID: 52742, 53246

MDVSA: 2012:069