Executive Summary

Summary
Title New arc packages fix insecure temporary files
Informations
Name DSA-843 First vendor Publication 2005-10-05
Vendor Debian Last vendor Modification 2005-10-05
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:P/I:N/A:N)
Cvss Base Score 2.1 Attack Range Local
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Two vulnerabilities have been discovered in the ARC archive program under Unix. The Common Vulnerabilities and Exposures project identifies the following problems:

CAN-2005-2945

Eric Romang discovered that the ARC archive program under Unix creates a temporary file with insecure permissions which may lead to an attacker stealing sensitive information.

CAN-2005-2992

Joey Schulze discovered that the temporary file was created in an insecure fashion as well, leaving it open to a classic symlink attack.

The old stable distribution (woody) does not contain arc packages.

For the stable distribution (sarge) these problems have been fixed in version 5.21l-1sarge1.

For the unstable distribution (sid) these problems have been fixed in version 5.21m-1.

We recommend that you upgrade your arc package.

Original Source

Url : http://www.debian.org/security/2005/dsa-843

OpenVAS Exploits

Date Description
2009-10-10 Name : SLES9: Security update for arc
File : nvt/sles9p5015664.nasl
2008-01-17 Name : Debian Security Advisory DSA 843-1 (arc)
File : nvt/deb_843_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
20176 arc Unspecified Symlink Arbitrary File Overwrite

19984 ARC marc Temporary Archive Permission Weakness Information Disclosure

19458 ARC arc Temporary Archive Permission Weakness Information Disclosure

Nessus® Vulnerability Scanner

Date Description
2009-09-24 Name : The remote SuSE 9 host is missing a security-related patch.
File : suse9_10496.nasl - Type : ACT_GATHER_INFO
2005-10-05 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-843.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-02-17 11:34:28
  • Multiple Updates
2013-05-11 12:19:11
  • Multiple Updates