Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.72177
Categoría:Debian Local Security Checks
Título:Debian Security Advisory DSA 2548-1 (tor)
Resumen:The remote host is missing an update to tor;announced via advisory DSA 2548-1.
Descripción:Summary:
The remote host is missing an update to tor
announced via advisory DSA 2548-1.

Vulnerability Insight:
Severel vulnerabilities have been discovered in Tor, an online privacy
tool.

CVE-2012-3518

Avoid an uninitialised memory read when reading a vote or consensus
document that has an unrecognized flavour name. This could lead to
a remote, resulting in denial of service.

CVE-2012-3519

Try to leak less information about what relays a client is choosing to
a side-channel attacker.

CVE-2012-4419

By providing specially crafted date strings to a victim tor instance,
an attacker can cause it to run into an assertion and shut down

Additionally the update to stable includes the following fixes:

- - When waiting for a client to renegotiate, don't allow it to add any
bytes to the input buffer. This fixes a potential DoS issue
[tor-5934, tor-6007].

For the stable distribution (squeeze), these problems have been fixed in
version 0.2.2.39-1.

For the unstable distribution, these problems have been fixed in version
0.2.3.22-rc-1.

Solution:
We recommend that you upgrade your tor packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2012-3518
http://security.gentoo.org/glsa/glsa-201301-03.xml
http://openwall.com/lists/oss-security/2012/08/21/6
https://lists.torproject.org/pipermail/tor-announce/2012-August/000086.html
http://secunia.com/advisories/50583
SuSE Security Announcement: openSUSE-SU-2012:1068 (Google Search)
http://lists.opensuse.org/opensuse-updates/2012-08/msg00048.html
Common Vulnerability Exposure (CVE) ID: CVE-2012-3519
Common Vulnerability Exposure (CVE) ID: CVE-2012-4419
http://lists.fedoraproject.org/pipermail/package-announce/2012-September/088006.html
http://openwall.com/lists/oss-security/2012/09/13/2
https://lists.torproject.org/pipermail/tor-talk/2012-September/025434.html
SuSE Security Announcement: openSUSE-SU-2012:1278 (Google Search)
http://lists.opensuse.org/opensuse-updates/2012-10/msg00005.html
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.