Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2003:058-1: cdrecord


Vulnerability Assessment Details

MDKSA-2003:058-1: cdrecord

Vulnerability Assessment Summary
Check for the version of the cdrecord package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory MDKSA-2003:058-1 (cdrecord).


A vulnerability in cdrecord was discovered that can be used to obtain root
access because Mandrake Linux ships with the cdrecord binary suid root and sgid
cdwriter.
Updated packages are provided that fix this vulnerability. You may also elect to
remove the suid and sgid bits from cdrecord manually, which can be done by
executing, as root:
chmod ug-s /usr/bin/cdrecord
This is not required to protect yourself from this particular vulnerability,
however.
Update:
Two additional format string problems were discovered by Olaf Kirch and an
updated patch has been applied to fix those problems as well.


Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:058-1
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security

Cables, Connectors

LENOVO DCG THINKSERVER TS 70TT000JUX TOSPELLER TS460 E3-1220 8G RAID
$1090.1
LENOVO DCG THINKSERVER TS 70TT000JUX  TOSPELLER TS460 E3-1220 8G RAID pictureApple Mac Pro RAID Card A1228 / A1247 2009 2010 2012 MB845Z/A 639-0108 8202591
$25.0
Apple Mac Pro RAID Card A1228 / A1247 2009 2010 2012 MB845Z/A 639-0108 8202591 pictureDell PERC H310 Adapter 8-Port 6Gb/s PCIe SAS RAID Controller Card HV52W
$29.95
Dell PERC H310 Adapter 8-Port 6Gb/s PCIe SAS RAID Controller Card HV52W pictureSweex PCIe SATA RAID Card 1x Sil3132R
$19.95
Sweex PCIe SATA RAID Card 1x Sil3132R picture


Discussions

No Discussions have been posted on this vulnerability.