Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.54575
Kategorie:Gentoo Local Security Checks
Titel:Gentoo Security Advisory GLSA 200405-15 (cadaver)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing updates announced in
advisory GLSA 200405-15.

There is a heap-based buffer overflow vulnerability in the neon library
used in cadaver, possibly leading to execution of arbitrary code when
connected to a malicious server.

Solution:
All users of cadaver should upgrade to the latest stable version:

# emerge sync

# emerge -pv '>=net-misc/cadaver-0.22.2'
# emerge '>=net-misc/cadaver-0.22.2'

http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200405-15
http://bugs.gentoo.org/show_bug.cgi?id=51461
http://www.gentoo.org/security/en/glsa/glsa-200405-13.xml

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: BugTraq ID: 10385
Common Vulnerability Exposure (CVE) ID: CVE-2004-0398
http://www.securityfocus.com/bid/10385
Bugtraq: 20040519 Advisory 06/2004: libneon date parsing vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=108498433632333&w=2
Bugtraq: 20040519 [OpenPKG-SA-2004.024] OpenPKG Security Advisory (neon) (Google Search)
http://marc.info/?l=bugtraq&m=108500057108022&w=2
Computer Incident Advisory Center Bulletin: O-148
http://www.ciac.org/ciac/bulletins/o-148.shtml
Conectiva Linux advisory: CLA-2004:841
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000841
Debian Security Information: DSA-506 (Google Search)
http://www.debian.org/security/2004/dsa-506
Debian Security Information: DSA-507 (Google Search)
http://www.debian.org/security/2004/dsa-507
https://bugzilla.fedora.us/show_bug.cgi?id=1552
http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0982.html
http://security.gentoo.org/glsa/glsa-200405-13.xml
http://security.gentoo.org/glsa/glsa-200405-15.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:049
http://www.osvdb.org/6302
http://www.redhat.com/support/errata/RHSA-2004-191.html
http://secunia.com/advisories/11638
http://secunia.com/advisories/11650
http://secunia.com/advisories/11673
XForce ISS Database: neon-library-nerfc1036parse-bo(16192)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16192
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.