Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.56785
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1064-1)
Summary:The remote host is missing an update for the Debian 'cscope' package(s) announced via the DSA-1064-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'cscope' package(s) announced via the DSA-1064-1 advisory.

Vulnerability Insight:
Jason Duell discovered that cscope, a source code browsing tool, does not verify the length of file names sourced in include statements, which may potentially lead to the execution of arbitrary code through specially crafted source code files.

For the old stable distribution (woody) this problem has been fixed in version 15.3-1woody3.

For the stable distribution (sarge) this problem has been fixed in version 15.5-1.1sarge1.

For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you upgrade your cscope package.

Affected Software/OS:
'cscope' package(s) on Debian 3.0, Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
6.9

CVSS Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-2541
http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html
BugTraq ID: 18050
http://www.securityfocus.com/bid/18050
BugTraq ID: 25159
http://www.securityfocus.com/bid/25159
Debian Security Information: DSA-1064 (Google Search)
http://www.debian.org/security/2006/dsa-1064
http://www.gentoo.org/security/en/glsa/glsa-200606-10.xml
http://sourceforge.net/tracker/index.php?func=detail&aid=1064875&group_id=4664&atid=104664
http://www.osvdb.org/11920
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10069
http://www.redhat.com/support/errata/RHSA-2009-1101.html
http://www.redhat.com/support/errata/RHSA-2009-1102.html
http://secunia.com/advisories/13237
http://secunia.com/advisories/20191
http://secunia.com/advisories/20564
http://secunia.com/advisories/26235
http://secunia.com/advisories/35462
http://www.vupen.com/english/advisories/2007/2732
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.