Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.840602
Categoría:Ubuntu Local Security Checks
Título:Ubuntu Update for pango1.0 vulnerabilities USN-1082-1
Resumen:Ubuntu Update for Linux kernel vulnerabilities USN-1082-1
Descripción:Summary:
Ubuntu Update for Linux kernel vulnerabilities USN-1082-1

Vulnerability Insight:
Marc Schoenefeld discovered that Pango incorrectly handled certain Glyph
Definition (GDEF) tables. If a user were tricked into displaying text with
a specially-crafted font, an attacker could cause Pango to crash, resulting
in a denial of service. This issue only affected Ubuntu 8.04 LTS and 9.10.
(CVE-2010-0421)

Dan Rosenberg discovered that Pango incorrectly handled certain FT_Bitmap
objects. If a user were tricked into displaying text with a specially-
crafted font, an attacker could cause a denial of service or execute
arbitrary code with privileges of the user invoking the program. The
default compiler options for affected releases should reduce the
vulnerability to a denial of service. (CVE-2011-0020)

It was discovered that Pango incorrectly handled certain memory
reallocation failures. If a user were tricked into displaying text in a way
that would cause a reallocation failure, an attacker could cause a denial
of service or execute arbitrary code with privileges of the user invoking
the program. This issue only affected Ubuntu 9.10, 10.04 LTS and 10.10.
(CVE-2011-0064)

Affected Software/OS:
pango1.0 vulnerabilities on Ubuntu 8.04 LTS,
Ubuntu 9.10,
Ubuntu 10.04 LTS,
Ubuntu 10.10

Solution:
Please Install the Updated Packages.

CVSS Score:
7.6

CVSS Vector:
AV:N/AC:H/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-0421
BugTraq ID: 38760
http://www.securityfocus.com/bid/38760
Debian Security Information: DSA-2019 (Google Search)
http://www.debian.org/security/2010/dsa-2019
http://www.mandriva.com/security/advisories?name=MDVSA-2010:121
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9417
http://www.redhat.com/support/errata/RHSA-2010-0140.html
http://securitytracker.com/id?1023711
http://secunia.com/advisories/39041
SuSE Security Announcement: SUSE-SR:2010:009 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.html
SuSE Security Announcement: SUSE-SR:2010:012 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
SuSE Security Announcement: SUSE-SR:2010:013 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
http://www.vupen.com/english/advisories/2010/0627
http://www.vupen.com/english/advisories/2010/0661
http://www.vupen.com/english/advisories/2010/1552
Common Vulnerability Exposure (CVE) ID: CVE-2011-0020
BugTraq ID: 45842
http://www.securityfocus.com/bid/45842
https://bugzilla.gnome.org/show_bug.cgi?id=639882
http://openwall.com/lists/oss-security/2011/01/18/6
http://openwall.com/lists/oss-security/2011/01/20/2
http://osvdb.org/70596
http://www.redhat.com/support/errata/RHSA-2011-0180.html
http://www.securitytracker.com/id?1024994
http://secunia.com/advisories/42934
http://secunia.com/advisories/43100
SuSE Security Announcement: SUSE-SR:2011:005 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
http://www.vupen.com/english/advisories/2011/0186
http://www.vupen.com/english/advisories/2011/0238
XForce ISS Database: pango-pango-bo(64832)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64832
Common Vulnerability Exposure (CVE) ID: CVE-2011-0064
BugTraq ID: 46632
http://www.securityfocus.com/bid/46632
Debian Security Information: DSA-2178 (Google Search)
http://www.debian.org/security/2011/dsa-2178
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056065.html
http://www.mandriva.com/security/advisories?name=MDVSA-2011:040
http://www.redhat.com/support/errata/RHSA-2011-0309.html
http://securitytracker.com/id?1025145
http://secunia.com/advisories/43559
http://secunia.com/advisories/43572
http://secunia.com/advisories/43578
http://secunia.com/advisories/43800
http://www.ubuntu.com/usn/USN-1082-1
http://www.vupen.com/english/advisories/2011/0543
http://www.vupen.com/english/advisories/2011/0555
http://www.vupen.com/english/advisories/2011/0558
http://www.vupen.com/english/advisories/2011/0584
http://www.vupen.com/english/advisories/2011/0683
XForce ISS Database: pango-hbbufferensure-bo(65770)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65770
CopyrightCopyright (c) 2011 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.