Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.831701
Categoría:Mandrake Local Security Checks
Título:Mandriva Update for libgdata MDVSA-2012:111 (libgdata)
Resumen:The remote host is missing an update for the 'libgdata'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'libgdata'
package(s) announced via the referenced advisory.

Vulnerability Insight:
A vulnerability has been discovered and corrected in libgdata:

It was found that previously libgdata, a GLib-based library for
accessing online service APIs using the GData protocol, did not
perform SSL certificates validation even for secured connections. An
application, linked against the libgdata library and holding the
trust about the other side of the connection being the valid owner
of the certificate, could be tricked into accepting of a spoofed SSL
certificate by mistake (MITM attack) (CVE-2012-1177).

The updated packages have been patched to correct this issue.

Affected Software/OS:
libgdata on Mandriva Linux 2011.0

Solution:
Please Install the Updated Packages.

CVSS Score:
5.1

CVSS Vector:
AV:N/AC:H/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2012-1177
Debian Security Information: DSA-2482 (Google Search)
http://www.debian.org/security/2012/dsa-2482
http://www.mandriva.com/security/advisories?name=MDVSA-2012:111
https://bugs.launchpad.net/ubuntu/+source/libgdata/+bug/938812
https://bugzilla.gnome.org/show_bug.cgi?id=671535
https://bugzilla.novell.com/show_bug.cgi?id=752088
http://www.openwall.com/lists/oss-security/2012/03/14/1
http://www.openwall.com/lists/oss-security/2012/03/14/3
http://www.openwall.com/lists/oss-security/2012/03/14/8
http://secunia.com/advisories/50432
http://www.ubuntu.com/usn/USN-1547-1
CopyrightCopyright (c) 2012 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.