home *** CD-ROM | disk | FTP | other *** search
/ Chip 2007 January, February, March & April / Chip-Cover-CD-2007-02.iso / Pakiet bezpieczenstwa / mini Pentoo LiveCD 2006.1 / mpentoo-2006.1.iso / modules / nessus-2.2.8.mo / usr / lib / nessus / plugins / mandrake_MDKSA-2004-082.nasl < prev    next >
Text File  |  2005-01-14  |  5KB  |  190 lines

  1. #
  2. # (C) Tenable Network Security
  3. #
  4. # This plugin text was extracted from Mandrake Linux Security Advisory MDKSA-2004:082
  5. #
  6.  
  7.  
  8. if ( ! defined_func("bn_random") ) exit(0);
  9. if(description)
  10. {
  11.  script_id(14331);
  12.  script_version ("$Revision: 1.2 $");
  13.  script_cve_id("CAN-2004-0597", "CAN-2004-0598", "CAN-2004-0599");
  14.  
  15.  name["english"] = "MDKSA-2004:082: mozilla";
  16.  
  17.  script_name(english:name["english"]);
  18.  
  19.  desc["english"] = "
  20. The remote host is missing the patch for the advisory MDKSA-2004:082 (mozilla).
  21.  
  22.  
  23. A number of security vulnerabilities in mozilla are addressed by this update for
  24. Mandrakelinux 10.0 users, including a fix for frame spoofing, a fixed popup
  25. XPInstall/security dialog bug, a fix for untrusted chrome calls, a fix for SSL
  26. certificate spoofing, a fix for stealing secure HTTP Auth passwords via DNS
  27. spoofing, a fix for insecure matching of cert names for non-FQDNs, a fix for
  28. focus redefinition from another domain, a fix for a SOAP parameter overflow, a
  29. fix for text drag on file entry, a fix for certificate DoS, and a fix for lock
  30. icon and cert spoofing.
  31. Additionally, mozilla for both Mandrakelinux 9.2 and 10.0 have been rebuilt to
  32. use the system libjpeg and libpng which addresses vulnerabilities discovered in
  33. libpng (ref: MDKSA-2004:079).
  34.  
  35.  
  36. Solution : http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:082
  37. Risk factor : High";
  38.  
  39.  
  40.  
  41.  script_description(english:desc["english"]);
  42.  
  43.  summary["english"] = "Check for the version of the mozilla package";
  44.  script_summary(english:summary["english"]);
  45.  
  46.  script_category(ACT_GATHER_INFO);
  47.  
  48.  script_copyright(english:"This script is Copyright (C) 2004 Tenable Network Security");
  49.  family["english"] = "Mandrake Local Security Checks";
  50.  script_family(english:family["english"]);
  51.  
  52.  script_dependencies("ssh_get_info.nasl");
  53.  script_require_keys("Host/Mandrake/rpm-list");
  54.  exit(0);
  55. }
  56.  
  57. include("rpm.inc");
  58. if ( rpm_check( reference:"libnspr4-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  59. {
  60.  security_hole(0);
  61.  exit(0);
  62. }
  63. if ( rpm_check( reference:"libnspr4-devel-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  64. {
  65.  security_hole(0);
  66.  exit(0);
  67. }
  68. if ( rpm_check( reference:"libnss3-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  69. {
  70.  security_hole(0);
  71.  exit(0);
  72. }
  73. if ( rpm_check( reference:"libnss3-devel-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  74. {
  75.  security_hole(0);
  76.  exit(0);
  77. }
  78. if ( rpm_check( reference:"mozilla-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  79. {
  80.  security_hole(0);
  81.  exit(0);
  82. }
  83. if ( rpm_check( reference:"mozilla-devel-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  84. {
  85.  security_hole(0);
  86.  exit(0);
  87. }
  88. if ( rpm_check( reference:"mozilla-enigmail-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  89. {
  90.  security_hole(0);
  91.  exit(0);
  92. }
  93. if ( rpm_check( reference:"mozilla-enigmime-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  94. {
  95.  security_hole(0);
  96.  exit(0);
  97. }
  98. if ( rpm_check( reference:"mozilla-irc-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  99. {
  100.  security_hole(0);
  101.  exit(0);
  102. }
  103. if ( rpm_check( reference:"mozilla-js-debugger-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  104. {
  105.  security_hole(0);
  106.  exit(0);
  107. }
  108. if ( rpm_check( reference:"mozilla-mail-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  109. {
  110.  security_hole(0);
  111.  exit(0);
  112. }
  113. if ( rpm_check( reference:"mozilla-spellchecker-1.6-12.1.100mdk", release:"MDK10.0", yank:"mdk") )
  114. {
  115.  security_hole(0);
  116.  exit(0);
  117. }
  118. if ( rpm_check( reference:"libnspr4-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  119. {
  120.  security_hole(0);
  121.  exit(0);
  122. }
  123. if ( rpm_check( reference:"libnspr4-devel-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  124. {
  125.  security_hole(0);
  126.  exit(0);
  127. }
  128. if ( rpm_check( reference:"libnss3-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  129. {
  130.  security_hole(0);
  131.  exit(0);
  132. }
  133. if ( rpm_check( reference:"libnss3-devel-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  134. {
  135.  security_hole(0);
  136.  exit(0);
  137. }
  138. if ( rpm_check( reference:"mozilla-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  139. {
  140.  security_hole(0);
  141.  exit(0);
  142. }
  143. if ( rpm_check( reference:"mozilla-devel-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  144. {
  145.  security_hole(0);
  146.  exit(0);
  147. }
  148. if ( rpm_check( reference:"mozilla-dom-inspector-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  149. {
  150.  security_hole(0);
  151.  exit(0);
  152. }
  153. if ( rpm_check( reference:"mozilla-enigmail-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  154. {
  155.  security_hole(0);
  156.  exit(0);
  157. }
  158. if ( rpm_check( reference:"mozilla-enigmime-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  159. {
  160.  security_hole(0);
  161.  exit(0);
  162. }
  163. if ( rpm_check( reference:"mozilla-irc-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  164. {
  165.  security_hole(0);
  166.  exit(0);
  167. }
  168. if ( rpm_check( reference:"mozilla-js-debugger-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  169. {
  170.  security_hole(0);
  171.  exit(0);
  172. }
  173. if ( rpm_check( reference:"mozilla-mail-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  174. {
  175.  security_hole(0);
  176.  exit(0);
  177. }
  178. if ( rpm_check( reference:"mozilla-spellchecker-1.4-13.3.92mdk", release:"MDK9.2", yank:"mdk") )
  179. {
  180.  security_hole(0);
  181.  exit(0);
  182. }
  183. if (rpm_exists(rpm:"mozilla-", release:"MDK10.0")
  184.  || rpm_exists(rpm:"mozilla-", release:"MDK9.2") )
  185. {
  186.  set_kb_item(name:"CAN-2004-0597", value:TRUE);
  187.  set_kb_item(name:"CAN-2004-0598", value:TRUE);
  188.  set_kb_item(name:"CAN-2004-0599", value:TRUE);
  189. }
  190.