Mandrake Linux Security Advisory : joe (MDKSA-2001:026)

This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.


Synopsis :

The remote Mandrake Linux host is missing a security update.

Description :

The joe text editor looks for configuration files in the current
working directory, the user's home directory, and finally in /etc/joe.
A malicious user could create their own .joerc configuration file and
attempt to get other users to use it. If this were to happen, the user
could potentially execute malicious commands with their own user ID
and privileges. This update removes joe's ability to use a .joerc
configuration file in the current working directory.

Solution :

Update the affected joe package.

Risk factor :

Medium / CVSS Base Score : 4.6
(CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P)

Family: Mandriva Local Security Checks

Nessus Plugin ID: 61900 ()

Bugtraq ID:

CVE ID: CVE-2001-0289

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now