Oval Definition:oval:com.redhat.rhsa:def:20040373
Revision Date:2004-08-04Version:502
Title:RHSA-2004:373: gnome-vfs security update (Low)
Description:GNOME VFS is the GNOME virtual file system. It provides a modular architecture and ships with several modules that implement support for file systems, HTTP, FTP, and others. The extfs backends make it possible to implement file systems for GNOME VFS using scripts.

Flaws have been found in several of the GNOME VFS extfs backend scripts. Red Hat Enterprise Linux ships with vulnerable scripts, but they are not used by default. An attacker who is able to influence a user to open a specially-crafted URI using gnome-vfs could perform actions as that user. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0494 to this issue.

Users of Red Hat Enterprise Linux should upgrade to these updated packages, which remove these unused scripts.
Family:unixClass:patch
Status:Reference(s):CVE-2004-0494
RHSA-2004:373-01
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND Package Information
  • gnome-vfs2-devel is earlier than 0:2.2.5-2E.1
  • AND gnome-vfs2-devel is signed with Red Hat master key
  • OR
  • gnome-vfs2 is earlier than 0:2.2.5-2E.1
  • AND gnome-vfs2 is signed with Red Hat master key
  • BACK