Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.66835
Categoría:Mandrake Local Security Checks
Título:Mandriva Security Advisory MDVSA-2010:038 (maildrop)
Resumen:NOSUMMARY
Descripción:Description:
The remote host is missing an update to maildrop
announced via advisory MDVSA-2010:038.

A vulnerability have been discovered and corrected in maildrop:

main.C in maildrop 2.3.0 and earlier, when run by root with the -d
option, uses the gid of root for execution of the .mailfilter file in
a user's home directory, which allows local users to gain privileges
via a crafted file (CVE-2010-0301).

The updated packages have been patched to correct this issue.

Affected: Corporate 4.0, Enterprise Server 5.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDVSA-2010:038

Risk factor : High

CVSS Score:
6.9

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-0301
1023515
http://securitytracker.com/id?1023515
38367
http://secunia.com/advisories/38367
38374
http://secunia.com/advisories/38374
DSA-1981
http://www.debian.org/security/2010/dsa-1981
[oss-security] 20100127 CVE id request: maildrop
http://marc.info/?l=oss-security&m=126462927918840&w=2
[oss-security] 20100128 Re: CVE id request: maildrop
http://marc.info/?l=oss-security&m=126468324913920&w=2
http://marc.info/?l=oss-security&m=126468551017070&w=2
http://marc.info/?l=oss-security&m=126468618017829&w=2
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=564601
http://www.courier-mta.org/maildrop/changelog.html
https://bugzilla.redhat.com/show_bug.cgi?id=559681
maildrop-group-priv-escalation(55980)
https://exchange.xforce.ibmcloud.com/vulnerabilities/55980
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.