Mandrake Linux Security Advisory : mgetty (MDKSA-2000:042)

High Nessus Plugin ID 61835


The remote Mandrake Linux host is missing one or more security updates.


There is a problem in the mgetty package, which contains a number of tools for sending and receiving faxes. The faxrunq tool uses a marker file in the /tmp directory, which is world-writable, in an insecure fashion. This problem, if exploited, allows malicious users to overwrite files on the system via a symlink attack which are owned by the user that is invoking faxrunq. All versions of mgetty prior to 1.1.22 are vulnerable.


Update the affected packages.

Plugin Details

Severity: High

ID: 61835

File Name: mandrake_MDKSA-2000-042.nasl

Version: $Revision: 1.3 $

Type: local

Published: 2012/09/06

Modified: 2013/05/31

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:mgetty, p-cpe:/a:mandriva:linux:mgetty-contrib, p-cpe:/a:mandriva:linux:mgetty-sendfax, p-cpe:/a:mandriva:linux:mgetty-viewfax, p-cpe:/a:mandriva:linux:mgetty-voice, cpe:/o:mandrakesoft:mandrake_linux:6.0, cpe:/o:mandrakesoft:mandrake_linux:6.1, cpe:/o:mandrakesoft:mandrake_linux:7.0, cpe:/o:mandrakesoft:mandrake_linux:7.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2000/08/31

Reference Information

MDKSA: 2000:042