home *** CD-ROM | disk | FTP | other *** search
/ Chip 2007 January, February, March & April / Chip-Cover-CD-2007-02.iso / Pakiet bezpieczenstwa / mini Pentoo LiveCD 2006.1 / mpentoo-2006.1.iso / modules / nessus-2.2.8.mo / usr / lib / nessus / plugins / mandrake_MDKSA-2003-063.nasl < prev    next >
Text File  |  2005-01-14  |  3KB  |  116 lines

  1. #
  2. # (C) Tenable Network Security
  3. #
  4. # This plugin text was extracted from Mandrake Linux Security Advisory MDKSA-2003:063-1
  5. #
  6.  
  7.  
  8. if ( ! defined_func("bn_random") ) exit(0);
  9. if(description)
  10. {
  11.  script_id(14046);
  12.  script_version ("$Revision: 1.3 $");
  13.  script_cve_id("CAN-2003-0189", "CAN-2003-0245");
  14.  
  15.  name["english"] = "MDKSA-2003:063-1: apache2";
  16.  
  17.  script_name(english:name["english"]);
  18.  
  19.  desc["english"] = "
  20. The remote host is missing the patch for the advisory MDKSA-2003:063-1 (apache2).
  21.  
  22.  
  23. Two vulnerabilities were discovered in the Apache web server that affect all 2.x
  24. versions prior to 2.0.46. The first, discovered by John Hughes, is a build
  25. system problem that allows remote attackers to prevent access to authenticated
  26. content when a threaded server is used. This only affects versions of Apache
  27. compiled with threaded server 'httpd.worker', which is not the default for
  28. Mandrake Linux.
  29. The second vulnerability, discovered by iDefense, allows remote attackers to
  30. cause a DoS (Denial of Service) condition and may also allow the execution of
  31. arbitrary code.
  32. The provided packages include back-ported fixes to correct these vulnerabilities
  33. and MandrakeSoft encourages all users to upgrade immediately.
  34. Update:
  35. The previous update mistakenly listed apache-conf packages which were never
  36. included, nor intended to be included, as part of the update.
  37.  
  38.  
  39. Solution : http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:063-1
  40. Risk factor : High";
  41.  
  42.  
  43.  
  44.  script_description(english:desc["english"]);
  45.  
  46.  summary["english"] = "Check for the version of the apache2 package";
  47.  script_summary(english:summary["english"]);
  48.  
  49.  script_category(ACT_GATHER_INFO);
  50.  
  51.  script_copyright(english:"This script is Copyright (C) 2004 Tenable Network Security");
  52.  family["english"] = "Mandrake Local Security Checks";
  53.  script_family(english:family["english"]);
  54.  
  55.  script_dependencies("ssh_get_info.nasl");
  56.  script_require_keys("Host/Mandrake/rpm-list");
  57.  exit(0);
  58. }
  59.  
  60. include("rpm.inc");
  61. if ( rpm_check( reference:"apache2-2.0.45-4.3mdk", release:"MDK9.1", yank:"mdk") )
  62. {
  63.  security_hole(0);
  64.  exit(0);
  65. }
  66. if ( rpm_check( reference:"apache2-common-2.0.45-4.3mdk", release:"MDK9.1", yank:"mdk") )
  67. {
  68.  security_hole(0);
  69.  exit(0);
  70. }
  71. if ( rpm_check( reference:"apache2-devel-2.0.45-4.3mdk", release:"MDK9.1", yank:"mdk") )
  72. {
  73.  security_hole(0);
  74.  exit(0);
  75. }
  76. if ( rpm_check( reference:"apache2-manual-2.0.45-4.3mdk", release:"MDK9.1", yank:"mdk") )
  77. {
  78.  security_hole(0);
  79.  exit(0);
  80. }
  81. if ( rpm_check( reference:"apache2-mod_dav-2.0.45-4.3mdk", release:"MDK9.1", yank:"mdk") )
  82. {
  83.  security_hole(0);
  84.  exit(0);
  85. }
  86. if ( rpm_check( reference:"apache2-mod_ldap-2.0.45-4.3mdk", release:"MDK9.1", yank:"mdk") )
  87. {
  88.  security_hole(0);
  89.  exit(0);
  90. }
  91. if ( rpm_check( reference:"apache2-mod_ssl-2.0.45-4.3mdk", release:"MDK9.1", yank:"mdk") )
  92. {
  93.  security_hole(0);
  94.  exit(0);
  95. }
  96. if ( rpm_check( reference:"apache2-modules-2.0.45-4.3mdk", release:"MDK9.1", yank:"mdk") )
  97. {
  98.  security_hole(0);
  99.  exit(0);
  100. }
  101. if ( rpm_check( reference:"apache2-source-2.0.45-4.3mdk", release:"MDK9.1", yank:"mdk") )
  102. {
  103.  security_hole(0);
  104.  exit(0);
  105. }
  106. if ( rpm_check( reference:"libapr0-2.0.45-4.3mdk", release:"MDK9.1", yank:"mdk") )
  107. {
  108.  security_hole(0);
  109.  exit(0);
  110. }
  111. if (rpm_exists(rpm:"apache2-", release:"MDK9.1") )
  112. {
  113.  set_kb_item(name:"CAN-2003-0189", value:TRUE);
  114.  set_kb_item(name:"CAN-2003-0245", value:TRUE);
  115. }
  116.