Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.882839
Kategorie:CentOS Local Security Checks
Titel:CentOS Update for nautilus CESA-2018:0223 centos7
Zusammenfassung:Check the version of nautilus
Beschreibung:Summary:
Check the version of nautilus

Vulnerability Insight:
Nautilus is the file manager and graphical
shell for the GNOME desktop.

Security Fix(es):

* An untrusted .desktop file with executable permission set could choose
its displayed name and icon, and execute commands without warning when
opened by the user. An attacker could use this flaw to trick a user into
opening a .desktop file disguised as a document, such as a PDF, and execute
arbitrary commands. (CVE-2017-14604)

Note: This update will change the behavior of Nautilus. Nautilus will now
prompt the user for confirmation when executing an untrusted .desktop file
for the first time, and then add it to the trusted file list. Desktop files
stored in the system directory, as specified by the XDG_DATA_DIRS
environment variable, are always considered trusted and executed without
prompt.

Affected Software/OS:
nautilus on CentOS 7

Solution:
Please Install the Updated Packages.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-14604
BugTraq ID: 101012
http://www.securityfocus.com/bid/101012
Debian Security Information: DSA-3994 (Google Search)
http://www.debian.org/security/2017/dsa-3994
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860268
https://bugzilla.gnome.org/show_bug.cgi?id=777991
https://github.com/GNOME/nautilus/commit/1630f53481f445ada0a455e9979236d31a8d3bb0
https://github.com/GNOME/nautilus/commit/bc919205bf774f6af3fa7154506c46039af5a69b
https://github.com/freedomofpress/securedrop/issues/2238
https://micahflee.com/2017/04/breaking-the-security-model-of-subgraph-os/
RedHat Security Advisories: RHSA-2018:0223
https://access.redhat.com/errata/RHSA-2018:0223
CopyrightCopyright (C) 2018 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.