Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.120316
Kategorie:Amazon Linux Local Security Checks
Titel:Amazon Linux: Security Advisory (ALAS-2014-359)
Zusammenfassung:The remote host is missing an update announced via the referenced Security Advisory.
Beschreibung:Summary:
The remote host is missing an update announced via the referenced Security Advisory.

Vulnerability Insight:
It was discovered that the asn1_get_bit_der() function of the libtasn1 library incorrectly reported the length of ASN.1-encoded data. Specially crafted ASN.1 input could cause an application using libtasn1 to perform an out-of-bounds access operation, causing the application to crash or, possibly, execute arbitrary code. (CVE-2014-3468 )Multiple incorrect buffer boundary check issues were discovered in libtasn1. Specially crafted ASN.1 input could cause an application using libtasn1 to crash. (CVE-2014-3467 )Multiple NULL pointer dereference flaws were found in libtasn1's asn1_read_value() function. Specially crafted ASN.1 input could cause an application using libtasn1 to crash, if the application used the aforementioned function in a certain way. (CVE-2014-3469 )

Solution:
Run yum update libtasn1 to update your system.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-3467
Debian Security Information: DSA-3056 (Google Search)
http://www.debian.org/security/2014/dsa-3056
http://www.mandriva.com/security/advisories?name=MDVSA-2015:116
http://lists.gnu.org/archive/html/help-libtasn1/2014-05/msg00006.html
RedHat Security Advisories: RHSA-2014:0594
http://rhn.redhat.com/errata/RHSA-2014-0594.html
RedHat Security Advisories: RHSA-2014:0596
http://rhn.redhat.com/errata/RHSA-2014-0596.html
RedHat Security Advisories: RHSA-2014:0687
http://rhn.redhat.com/errata/RHSA-2014-0687.html
RedHat Security Advisories: RHSA-2014:0815
http://rhn.redhat.com/errata/RHSA-2014-0815.html
http://secunia.com/advisories/58591
http://secunia.com/advisories/58614
http://secunia.com/advisories/59021
http://secunia.com/advisories/59057
http://secunia.com/advisories/59408
http://secunia.com/advisories/60320
http://secunia.com/advisories/60415
http://secunia.com/advisories/61888
SuSE Security Announcement: SUSE-SU-2014:0758 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00002.html
SuSE Security Announcement: SUSE-SU-2014:0788 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00015.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-3469
Common Vulnerability Exposure (CVE) ID: CVE-2014-3468
CopyrightCopyright (C) 2015 Eero Volotinen

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.