|
From: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Date: Thu Aug 12 2004 - 09:15:19 EDT
-----BEGIN PGP SIGNED MESSAGE-----
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
Nessus contains a vulnerability allowing a user to perform a privilege
Background
Nessus is a free and powerful network security scanner.
Affected packages
-------------------------------------------------------------------
Description
A race condition can occur in "nessus-adduser" if the user has not
Impact
A malicious user could exploit this bug to escalate privileges to the
Workaround
There is no known workaround at this time. All users are encouraged to
Resolution
All Nessus users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=net-analyzer/nessus-2.0.12"
References
[ 1 ] Secunia Advisory
Availability
This GLSA and any updates to it are available for viewing at
http://security.gentoo.org/glsa/glsa-200408-11.xml
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the
License
Copyright 2004 Gentoo Foundation, Inc; referenced text
The contents of this document are licensed under the
http://creativecommons.org/licenses/by-sa/1.0
iD8DBQFBG21qzKC5hMHO6rkRAuO/AJoCPcUtvwHCLCrl1ZqkvS11+j1NowCeJ27o
_______________________________________________
This archive was generated by hypermail 2.1.8 : Thu Aug 12 2004 - 12:02:10 EDT |
Custom Search
|