Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.52427
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: isc-dhcp3-relay, isc-dhcp3-server
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to the system
as announced in the referenced advisory.

The following packages are affected:
isc-dhcp3-relay
isc-dhcp3-server

CVE-2004-0460
Buffer overflow in the logging capability for the DHCP daemon (DHCPD)
for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause
a denial of service (server crash) and possibly execute arbitrary code
via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST,
(4) ACK, or (5) NAK messages, which can generate a long string when
writing to a log file.

Solution:
Update your system with the appropriate patches or
software upgrades.

http://www.osvdb.org/7237
http://www.securityfocus.com/archive/1/366801
http://www.securityfocus.com/archive/1/367286
http://www.vuxml.org/freebsd/7a9d5dfe-c507-11d8-8898-000d6111a684.html

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: BugTraq ID: 10590
Common Vulnerability Exposure (CVE) ID: CVE-2004-0460
http://www.securityfocus.com/bid/10590
Bugtraq: 20040622 DHCP Vuln // no code 0day // (Google Search)
http://marc.info/?l=bugtraq&m=108795911203342&w=2
Bugtraq: 20040628 ISC DHCP overflows (Google Search)
http://marc.info/?l=bugtraq&m=108843959502356&w=2
Bugtraq: 20040708 [OpenPKG-SA-2004.031] OpenPKG Security Advisory (dhcpd) (Google Search)
http://marc.info/?l=bugtraq&m=108938625206063&w=2
Cert/CC Advisory: TA04-174A
http://www.us-cert.gov/cas/techalerts/TA04-174A.html
CERT/CC vulnerability note: VU#317350
http://www.kb.cert.org/vuls/id/317350
http://www.mandriva.com/security/advisories?name=MDKSA-2004:061
http://secunia.com/advisories/23265
SuSE Security Announcement: SuSE-SA:2004:019 (Google Search)
http://www.novell.com/linux/security/advisories/2004_19_dhcp_server.html
XForce ISS Database: dhcp-ascii-log-bo(16475)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16475
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.