Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50685
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2003:021 (krb5)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to krb5
announced via advisory MDKSA-2003:021.

A vulnerability was discovered in the Kerberos FTP client. When the
client retrieves a file that has a filename beginning with a pipe
character, the FTP client will pass that filename to the command
shell in a system() call. This could allow a malicious remote FTP
server to write to files outside of the current directory or even
execute arbitrary commands as the user using the FTP client.

Affected versions: 8.1, 8.2, 9.0, Multi Network Firewall 8.2

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2003:021
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0041

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: BugTraq ID: 396
Common Vulnerability Exposure (CVE) ID: CVE-2003-0041
http://www.mandriva.com/security/advisories?name=MDKSA-2003:021
http://www.redhat.com/support/errata/RHSA-2003-020.html
http://secunia.com/advisories/7979
http://secunia.com/advisories/8114
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.html
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.