Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.58382
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2007:102 (php)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to php
announced via advisory MDKSA-2007:102.

A heap buffer overflow flaw was found in the xmlrpc extension for PHP.
A script that implements an XML-RPC server using this extension could
allow a remote attacker to execute arbitrary code as the apache user.
This flaw does not, however, affect PHP applications using the pure-PHP
XML_RPC class provided via PEAR (CVE-2007-1864).

A flaw was found in the ftp extension for PHP. A script using
this extension to provide access to a private FTP server and which
passed untrusted script input directly to any function provided by
this extension could allow a remote attacker to send arbitrary FTP
commands to the server (CVE-2007-2509).

A buffer overflow flaw was found in the soap extension for PHP
in the handling of an HTTP redirect response when using the SOAP
client provided by the extension with an untrusted SOAP server
(CVE-2007-2510).

A buffer overflow in the user_filter_factory_create() function has
unknown impact and local attack vectors (CVE-2007-2511).

Updated packages have been patched to prevent this issue.

Affected: 2007.0, 2007.1, Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2007:102

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2007-1864
BugTraq ID: 23813
http://www.securityfocus.com/bid/23813
Debian Security Information: DSA-1330 (Google Search)
http://www.debian.org/security/2007/dsa-1330
Debian Security Information: DSA-1331 (Google Search)
http://www.debian.org/security/2007/dsa-1331
http://security.gentoo.org/glsa/glsa-200705-19.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:102
http://www.mandriva.com/security/advisories?name=MDKSA-2007:103
http://osvdb.org/34674
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11257
RedHat Security Advisories: RHSA-2007:0348
https://rhn.redhat.com/errata/RHSA-2007-0348.html
http://www.redhat.com/support/errata/RHSA-2007-0349.html
http://www.redhat.com/support/errata/RHSA-2007-0355.html
http://www.securitytracker.com/id?1018024
http://secunia.com/advisories/25187
http://secunia.com/advisories/25191
http://secunia.com/advisories/25255
http://secunia.com/advisories/25445
http://secunia.com/advisories/25660
http://secunia.com/advisories/25938
http://secunia.com/advisories/25945
http://secunia.com/advisories/26048
http://secunia.com/advisories/26102
http://secunia.com/advisories/27377
SuSE Security Announcement: SUSE-SA:2007:044 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2007-07/msg00006.html
http://www.trustix.org/errata/2007/0017/
http://www.ubuntu.com/usn/usn-485-1
http://www.vupen.com/english/advisories/2007/2187
Common Vulnerability Exposure (CVE) ID: CVE-2007-2509
BugTraq ID: 23818
http://www.securityfocus.com/bid/23818
Bugtraq: 20070323 CRLF injection in PHP ftp function (Google Search)
http://www.securityfocus.com/archive/1/463596/100/0/threaded
Debian Security Information: DSA-1295 (Google Search)
http://www.debian.org/security/2007/dsa-1295
Debian Security Information: DSA-1296 (Google Search)
http://www.debian.org/security/2007/dsa-1296
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10839
http://www.redhat.com/support/errata/RHSA-2007-0888.html
RedHat Security Advisories: RHSA-2007:0889
http://rhn.redhat.com/errata/RHSA-2007-0889.html
http://www.securitytracker.com/id?1018022
http://secunia.com/advisories/25318
http://secunia.com/advisories/25365
http://secunia.com/advisories/25372
http://secunia.com/advisories/26967
http://secunia.com/advisories/27351
http://securityreason.com/securityalert/2672
http://www.ubuntu.com/usn/usn-462-1
XForce ISS Database: php-ftpputcmd-crlf-injection(34413)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34413
Common Vulnerability Exposure (CVE) ID: CVE-2007-2510
BugTraq ID: 24034
http://www.securityfocus.com/bid/24034
http://osvdb.org/34675
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10715
http://www.securitytracker.com/id?1018023
Common Vulnerability Exposure (CVE) ID: CVE-2007-2511
http://osvdb.org/34676
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.