Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.50581
Kategorie:Mandrake Local Security Checks
Titel:Mandrake Security Advisory MDKSA-2004:100 (mpg123)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing an update to mpg123
announced via advisory MDKSA-2004:100.

A vulnerability in mpg123 was discovered by Davide Del Vecchio where
certain malicious mpg3/2 files would cause mpg123 to fail header
checks, which could in turn allow arbitrary code to be executed with
the privileges of the user running mpg123 (CVE-2004-0805).

As well, an older vulnerability in mpg123, where a response from a
remote HTTP server could overflow a buffer allocated on the heap, is
also fixed in these packages. This vulnerability could also
potentially permit the execution of arbitray code with the privileges
of the user running mpg123 (CVE-2003-0865).

Affected versions: 10.0, 9.2, Corporate Server 2.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2004:100
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0865
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0805

Risk factor : High

CVSS Score:
7.5

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2004-0805
BugTraq ID: 11121
http://www.securityfocus.com/bid/11121
Bugtraq: 20040916 mpg123 buffer overflow vulnerability (Google Search)
http://www.securityfocus.com/archive/1/374433
Debian Security Information: DSA-564 (Google Search)
http://www.debian.org/security/2004/dsa-564
http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/026151.html
http://www.gentoo.org/security/en/glsa/glsa-200409-20.xml
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:100
http://www.alighieri.org/advisories/advisory-mpg123.txt
XForce ISS Database: mpg123-layer2c-bo(17287)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17287
Common Vulnerability Exposure (CVE) ID: CVE-2003-0865
BugTraq ID: 8680
http://www.securityfocus.com/bid/8680
Bugtraq: 20030923 mpg123[v0.59r,v0.59s]: remote client-side heap corruption exploit. (Google Search)
http://www.securityfocus.com/archive/1/338641
Bugtraq: 20030930 GLSA: mpg123 (200309-17) (Google Search)
http://marc.info/?l=bugtraq&m=106493686331198&w=2
Conectiva Linux advisory: CLA-2003:781
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000781
Debian Security Information: DSA-435 (Google Search)
http://www.debian.org/security/2004/dsa-435
SCO Security Bulletin: CSSA-2004-002.0
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2004-002.0/CSSA-2004-002.0.txt
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.