Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.71495
Categoría:Debian Local Security Checks
Título:Debian Security Advisory DSA 2518-1 (krb5)
Resumen:The remote host is missing an update to krb5;announced via advisory DSA 2518-1.
Descripción:Summary:
The remote host is missing an update to krb5
announced via advisory DSA 2518-1.

Vulnerability Insight:
Emmanuel Bouillon from NCI Agency discovered multiple vulnerabilities in MIT
Kerberos, a daemon implementing the network authentication protocol.

CVE-2012-1014

By sending specially crafted AS-REQ (Authentication Service Request) to a KDC
(Key Distribution Center), an attacker could make it free an uninitialized
pointer, corrupting the heap. This can lead to process crash or even arbitrary
code execution.
.
This CVE only affects testing (wheezy) and unstable (sid) distributions.

CVE-2012-1015

By sending specially crafted AS-REQ to a KDC, an attacker could make it
dereference an uninitialized pointer, leading to process crash or even
arbitrary code execution

In both cases, arbitrary code execution is believed to be difficult to achieve,
but might not be impossible.

For the stable distribution (squeeze), this problem has been fixed in
version 1.8.3+dfsg-4squeeze6.

For the testing distribution (wheezy), this problem has been fixed in
version 1.10.1+dfsg-2.

For the unstable distribution (sid), this problem has been fixed in
version 1.10.1+dfsg-2.

Solution:
We recommend that you upgrade your krb5 packages.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2012-1014
Debian Security Information: DSA-2518 (Google Search)
http://www.debian.org/security/2012/dsa-2518
SuSE Security Announcement: openSUSE-SU-2012:0967 (Google Search)
http://lists.opensuse.org/opensuse-updates/2012-08/msg00016.html
Common Vulnerability Exposure (CVE) ID: CVE-2012-1015
http://www.mandriva.com/security/advisories?name=MDVSA-2012:120
RedHat Security Advisories: RHSA-2012:1131
http://rhn.redhat.com/errata/RHSA-2012-1131.html
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.