Summary
The remote host is missing an update to joe
announced via advisory DSA 041-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20041-1
Insight
Christer Öberg of Wkit Security AB found a problem in joe (Joe's Own Editor). joe will look for a configuration file in three locations: the current directory, the users homedirectory ($HOME) and in /etc/joe. Since the configuration file can define commands joe will run (for example to check spelling) reading it from the current directory can be dangerous: an attacker can leave a .joerc file in a writable directory, which would be read when a unsuspecting user starts joe in that directory.
This has been fixed in version 2.8-15.3 and we recommend that you upgrade your joe package immediately.
Severity
Classification
-
CVE CVE-2001-0289 -
CVSS Base Score: 4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities