This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.
The remote Mandriva Linux host is missing one or more security
Multiple vulnerabilities was found and corrected in busybox :
The decompress function in ncompress allows remote attackers to cause
a denial of service (crash), and possibly execute arbitrary code, via
crafted data that leads to a buffer underflow (CVE-2006-1168).
A missing DHCP option checking / sanitization flaw was reported for
multiple DHCP clients. This flaw may allow DHCP server to trick DHCP
clients to set e.g. system hostname to a specially crafted value
containing shell special characters. Various scripts assume that
hostname is trusted, which may lead to code execution when hostname is
specially crafted (CVE-2011-2716).
Additionally for Mandriva Enterprise Server 5 various problems in the
ka-deploy and uClibc packages was discovered and fixed with this
The updated packages have been patched to correct these issues.
The wrong set of packages was sent out with the MDVSA-2012:129
advisory that lacked the fix for CVE-2006-1168. This advisory provides
the correct packages.
Update the affected busybox and / or busybox-static packages.
Risk factor :
High / CVSS Base Score : 7.5