Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA304] DSA-304-1 lv


Vulnerability Assessment Details

[DSA304] DSA-304-1 lv

Vulnerability Assessment Summary
DSA-304-1 lv

Detailed Explanation for this Vulnerability Assessment

Leonard Stiles discovered that lv, a multilingual file viewer, would
read options from a configuration file in the current directory.
Because such a file could be placed there by a malicious user, and lv
configuration options can be used to execute commands, this
represented a security vulnerability. A possible hacker could gain the
rights of the user invoking lv, including root.
For the stable distribution (woody) this problem has been fixed in
version 4.49.4-7woody2.
For the old stable distribution (potato) this problem has been fixed
in version 4.49.3-4potato2.
For the unstable distribution (sid) this problem is fixed in version
4.49.5-2.
We recommend that you update your lv package.


Solution : http://www.debian.org/security/2003/dsa-304
Network Security Threat Level: High

Networks Security ID: 7613

Vulnerability Assessment Copyright: This script is (C) 2005 Michel Arboi

Cables, Connectors

Grandstream Networks HandyTone 503 FXS FXO VoIP Adapter
$132.13
Grandstream Networks HandyTone 503 FXS FXO VoIP Adapter picturePrepaid Calling Card system VOIP UTELUS h323-SIP Softswitch Hosting 100 Port
$200.0
Prepaid Calling Card system VOIP UTELUS h323-SIP Softswitch Hosting 100 Port pictureCisco CP-7937G 7937 - Unified IP Conference Station PoE VOIP Phone Telephone
$94.96
Cisco CP-7937G 7937 - Unified IP Conference Station PoE VOIP Phone Telephone pictureHypermedia HG-7032Q6P VOIP SMS PRO 32 GSM Channel Cellular Gateway Sim Server
$12661.44
Hypermedia HG-7032Q6P VOIP SMS PRO 32 GSM Channel Cellular Gateway Sim Server picture


Discussions

No Discussions have been posted on this vulnerability.