Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2005:133: netpbm


Vulnerability Assessment Details

MDKSA-2005:133: netpbm

Vulnerability Assessment Summary
Check for the version of the netpbm package

Detailed Explanation for this Vulnerability Assessment

The remote host is missing the patch for the advisory MDKSA-2005:133 (netpbm).



Max Vozeler discovered that pstopnm, a part of the netpbm graphics utility
suite, would call the GhostScript interpreter on untrusted PostScript files
without using the -dSAFER option when converting a PostScript file into a PBM,
PGM, or PNM file. This could result in the execution of arbitrary commands with
the rights of the user running pstopnm if they could be convinced to try to
convert a malicious PostScript file.

The updated packages have been patched to correct this problem.



Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2005:133
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 Tenable Network Security

Cables, Connectors

Cisco DS-SFP-FCGE-SW 4Gbps Fibre Channel SFP Transceiver Genuine
$4.95
Cisco DS-SFP-FCGE-SW 4Gbps Fibre Channel SFP Transceiver Genuine pictureIBM 44X1962 IBM Brocade 8 Gb SFP+SW Optical Tr ansceiver
$152.0
IBM 44X1962 IBM Brocade 8 Gb SFP+SW Optical Tr ansceiver pictureMikroTik CCR1072-1G-8S+ Gx72 Core 1.2GHz per Core 8 SFP+ Ports Cloud Core Router
$2000.0
MikroTik CCR1072-1G-8S+ Gx72 Core 1.2GHz per Core 8 SFP+ Ports Cloud Core Router pictureIntel X520-DA1 single port SFP+ 10Gb Ethernet network card low profile
$68.99
Intel X520-DA1 single port SFP+ 10Gb Ethernet network card low profile  picture


Discussions

No Discussions have been posted on this vulnerability.