############################################################################## # # Red Hat local check # # Revision: # $Revision: 1.4 $ # # ------------------------------------------------------------------------ # # This program was written by StillSecure and is licensed under the GNU # GPL license. Please see below for details. This header contains # information regarding licensing terms under the GPL, and information # regarding obtaining source code from the Author. Consequently, pursuant # to section 3(c) of the GPL, you must accompany the information found in # this header with any distribution you make of this Program. # # Copyright (C) 2005. Latis Networks, Inc (d/b/a StillSecure) # Please see www.stillsecure.com/opensource and # www.stillsecure.com/policies/copyright.php for further information. # # ------------------------------------------------------------------------ # # Obtaining Source Code from StillSecure # # StillSecure delivers network security solutions that protect IT # business infrastructure. The integrated StillSecure suite provides # preventative defense, enables compliance with regulatory information # security policies, and actively blocks network attacks. StillSecure # manages and reduces risk from network attack and noncompliance for some # of the largest organizations in the healthcare, financial services, # government, and education sectors. # # VAM - vulnerability management platform # StillSecure VAM manages the vulnerability remediation process from # end-to-end, allowing you to quickly and systematically fix # vulnerabilities that expose your organization to attack. # # Border Guard - network intrusion detection/prevention # StillSecure Border Guard, named SC Magazine's best IPS of 2004, is a # network intrusion detection/prevention system (IDS/IPS) that identifies # and terminates viruses, worms, Trojans, port scans, and other malicious # traffic before they enter the network. # # Safe Access - endpoint policy compliance # Information Security's Hotpick in 2004, SillSecure Safe Access # protects the network by ensuring that endpoint devices are free from # threats and in compliance with IT security policies. # # StillSecure will offer, for three years from the date this program was # released, to give any third party, for a charge no more than # StillSecure's cost of physically performing source distribution, a # complete machine-readable copy of the corresponding source code, # distributed under the terms of the GPL, on a medium customarily used for # software interchange. # # ------------------------------------------------------------------------ # # About the license for this program: # # This program is free software; you can redistribute it and/or modify it # under the terms of the GNU General Public License v2 as published by the # Free Software Foundation. This program is distributed WITHOUT ANY # WARRANTY; without even the implied warranty of MERCHANTABILITY or # FITNESS FOR A PARTICULAR PURPOSE. You should have received a copy of # the GNU General Public License with this program; if not, go to # www.gnu.org/licenses/gpl.txt # # ------------------------------------------------------------------------ # # For further information regarding this program or to purchase any # StillSecure products please write to sales@stillsecure.com or call # (303) 381-3800. # # LOCAL_CHECK=YES ############################################################################## # The plugin text is copyright Red Hat, Inc. if ( ! defined_func("bn_random") ) exit(0); if(description) { script_id(401629); script_version ("$Revision: 1.4 $"); script_cve_id("CVE-2005-2693","CAN-2005-2693"); name["english"] = "RHEL4 : cvs security update"; script_name(english:name["english"]); desc["english"] = ' Details An updated cvs package that fixes a security bug is now available. This update has been rated as having low security impact by the Red Hat Security Response Team. CVS (Concurrent Version System) is a version control system. An insecure temporary file usage was found in the cvsbug program. It is possible that a local user could leverage this issue to execute arbitrary instructions as the user running cvsbug. The Common Vulnerabilities and Exposures project assigned the name CAN-2005-2693 to this issue. All users of cvs should upgrade to this updated package, which includes a patch to correct this issue. Description truncated, please see reference URL below for more information. Reference: http://rhn.redhat.com//errata/RHSA-2005-756.html Packages affected: Refer to vendor website for up to date details on packages affected. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: http://www.redhat.com/docs/manuals/enterprise/ Risk factor : Low'; script_description(english:desc["english"]); summary["english"] = "RHEL4 : cvs security update"; script_summary(english:summary["english"]); script_category(ACT_GATHER_INFO); script_copyright(english:"Copyright (C) 2005-2006 StillSecure"); family["english"] = "Red Hat Local Security Checks"; script_family(english:family["english"]); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/RedHat/rpm-list"); exit(0); } include("rpm.inc"); if ( rpm_check(reference:"cvs-1.11.2-28", release:"RHEL4") ) { security_hole(0); exit(0); } if ( rpm_check(reference:"cvs-1.11.17-8.RHEL4", release:"RHEL4") ) { security_hole(0); exit(0); } if ( rpm_check(reference:"cvs-1.11.1p1-19", release:"RHEL4") ) { security_hole(0); exit(0); } if ( rpm_exists(rpm:"cvs-", release:"RHEL4") ) { set_kb_item(name:"CVE-2005-2693", value:TRUE); set_kb_item(name:"CAN-2005-2693", value:TRUE); exit(0); } set_kb_item(name:"RHSA-2005-756", value:TRUE);