Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.52249
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: tiff
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to the system
as announced in the referenced advisory.

The following packages are affected:
tiff
linux-tiff
pdflib

CVE-2004-1308
Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff
3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via
a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry
with a -1 entry count, which leads to a heap-based buffer overflow.

Solution:
Update your system with the appropriate patches or
software upgrades.

http://www.idefense.com/application/poi/display?id=174&type=vulnerabilities
http://www.vuxml.org/freebsd/fc7e6a42-6012-11d9-a9e7-0001020eed82.html

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: BugTraq ID: 12075
Common Vulnerability Exposure (CVE) ID: CVE-2004-1308
http://lists.apple.com/archives/security-announce/2005/May/msg00001.html
Cert/CC Advisory: TA05-136A
http://www.us-cert.gov/cas/techalerts/TA05-136A.html
CERT/CC vulnerability note: VU#125598
http://www.kb.cert.org/vuls/id/125598
Conectiva Linux advisory: CLA-2005:920
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000920
Debian Security Information: DSA-617 (Google Search)
http://www.debian.org/security/2004/dsa-617
http://www.idefense.com/application/poi/display?id=174&type=vulnerabilities
http://www.mandriva.com/security/advisories?name=MDKSA-2005:052
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100117
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9392
http://www.redhat.com/support/errata/RHSA-2005-019.html
http://www.redhat.com/support/errata/RHSA-2005-035.html
http://secunia.com/advisories/13776
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101677-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201072-1
SuSE Security Announcement: SUSE-SA:2005:001 (Google Search)
http://www.novell.com/linux/security/advisories/2005_01_libtiff_tiff.html
XForce ISS Database: libtiff-tiff-tdircount-bo(18637)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18637
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.