Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.64480
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 1841-1 (git-core)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to git-core
announced via advisory DSA 1841-1.

It was discovered that git-daemon which is part of git-core, a popular
distributed revision control system, is vulnerable to denial of service
attacks caused by a programming mistake in handling requests containing
extra unrecognized arguments which results in an infinite loop. While
this is no problem for the daemon itself as every request will spawn a
new git-daemon instance, this still results in a very high CPU consumption
and might lead to denial of service conditions.


For the oldstable distribution (etch), this problem has been fixed in
version 1.4.4.4-4+etch3.

For the stable distribution (lenny), this problem has been fixed in
version 1.5.6.5-3+lenny2.

For the testing distribution (squeeze), this problem has been fixed in
version 1:1.6.3.3-1.

For the unstable distribution (sid), this problem has been fixed in
version 1:1.6.3.3-1.


We recommend that you upgrade your git-core packages.

Solution:
http://www.securityspace.com/smysecure/catid.html?in=DSA%201841-1

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-2108
BugTraq ID: 35338
http://www.securityfocus.com/bid/35338
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01045.html
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01126.html
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01056.html
http://security.gentoo.org/glsa/glsa-200907-05.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2009:155
http://article.gmane.org/gmane.comp.version-control.git/120733
http://thread.gmane.org/gmane.comp.version-control.git/120724
https://www.redhat.com/archives/fedora-security-list/2009-June/msg00000.html
http://www.openwall.com/lists/oss-security/2009/06/12/1
http://osvdb.org/55034
http://www.securitytracker.com/id?1022398
http://secunia.com/advisories/35437
http://secunia.com/advisories/35730
http://www.vupen.com/english/advisories/2009/1579
XForce ISS Database: gitdaemon-xinetd-dos(51083)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51083
CopyrightCopyright (c) 2009 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.