Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.841683
Categoría:Ubuntu Local Security Checks
Título:Ubuntu Update for openssl USN-2079-1
Resumen:The remote host is missing an update for the 'openssl'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'openssl'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Anton Johansson discovered that OpenSSL incorrectly handled certain invalid
TLS handshakes. A remote attacker could use this issue to cause OpenSSL to
crash, resulting in a denial of service. (CVE-2013-4353)

Ron Barber discovered that OpenSSL used an incorrect data structure to
obtain a version number. A remote attacker could use this issue to cause
OpenSSL to crash, resulting in a denial of service. (CVE-2013-6449)

Dmitry Sobinov discovered that OpenSSL incorrectly handled certain DTLS
retransmissions. A remote attacker could use this issue to cause OpenSSL to
crash, resulting in a denial of service. (CVE-2013-6450)

This update also disables the default use of the RdRand feature of certain
Intel CPUs as the sole source of entropy.

Affected Software/OS:
openssl on Ubuntu 13.10,
Ubuntu 13.04,
Ubuntu 12.10,
Ubuntu 12.04 LTS

Solution:
Please Install the Updated Packages.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2013-4353
Debian Security Information: DSA-2837 (Google Search)
http://www.debian.org/security/2014/dsa-2837
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html
RedHat Security Advisories: RHSA-2014:0015
http://rhn.redhat.com/errata/RHSA-2014-0015.html
RedHat Security Advisories: RHSA-2014:0041
http://rhn.redhat.com/errata/RHSA-2014-0041.html
SuSE Security Announcement: openSUSE-SU-2014:0094 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-01/msg00065.html
SuSE Security Announcement: openSUSE-SU-2014:0096 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-01/msg00067.html
SuSE Security Announcement: openSUSE-SU-2014:0099 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-01/msg00070.html
http://www.ubuntu.com/usn/USN-2079-1
Common Vulnerability Exposure (CVE) ID: CVE-2013-6449
BugTraq ID: 64530
http://www.securityfocus.com/bid/64530
Bugtraq: 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Debian Security Information: DSA-2833 (Google Search)
http://www.debian.org/security/2014/dsa-2833
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124833.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124854.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124858.html
http://seclists.org/fulldisclosure/2014/Dec/23
http://security.gentoo.org/glsa/glsa-201412-39.xml
http://www.securitytracker.com/id/1029548
SuSE Security Announcement: openSUSE-SU-2014:0012 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-01/msg00006.html
SuSE Security Announcement: openSUSE-SU-2014:0015 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-01/msg00009.html
SuSE Security Announcement: openSUSE-SU-2014:0018 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-01/msg00012.html
SuSE Security Announcement: openSUSE-SU-2014:0048 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-01/msg00031.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-6450
BugTraq ID: 64618
http://www.securityfocus.com/bid/64618
http://www.securitytracker.com/id/1029549
http://www.securitytracker.com/id/1031594
SuSE Security Announcement: openSUSE-SU-2014:0049 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-01/msg00032.html
CopyrightCopyright (C) 2014 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.