Executive Summary
Summary | |
---|---|
Title | New fte packages fix buffer overflows |
Informations | |||
---|---|---|---|
Name | DSA-472 | First vendor Publication | 2004-04-03 |
Vendor | Debian | Last vendor Modification | 2004-04-03 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Steve Kemp and Jaguar discovered a number of buffer overflow vulnerabilities in vfte, a version of the fte editor which runs on the Linux console, found in the package fte-console. This program is setuid root in order to perform certain types of low-level operations on the console. Due to these bugs, setuid privilege has been removed from vfte, making it only usable by root. We recommend using the terminal version (in the fte-terminal package) instead, which runs on any capable terminal including the Linux console. For the stable distribution (woody) these problems have been fixed in version 0.49.13-15woody1. For the unstable distribution (sid) these problems have been fixed in version 0.50.0-1.1. We recommend that you update your fte package. |
Original Source
Url : http://www.debian.org/security/2004/dsa-472 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Os | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 472-1 (fte) File : nvt/deb_472_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
4938 | FTE Text Editor vfte Overflow A local overflow exists in FTE Text Editor. The FTE Text Editor lacks adequate bounds checking on the command line arguments. With a specially crafted request, an attacker can cause the setuid binary "vfte" to execute arbitrary commands as root, resulting in a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-472.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:33:11 |
|