Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.58085
Kategorie:Mandrake Local Security Checks
Titel:Mandrake Security Advisory MDKSA-2007:043 (clamav)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing an update to clamav
announced via advisory MDKSA-2007:043.

Clam AntiVirus ClamAV before 0.90 does not close open file descriptors
under certain conditions, which allows remote attackers to cause a
denial of service (file descriptor consumption and failed scans) via
CAB archives with a cabinet header record length of zero, which causes
a function to return without closing a file descriptor. (CVE-2007-0897)

Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV
before 0.90 allows remote attackers to overwrite arbitrary files via a
.. (dot dot) in the id MIME header parameter in a multi-part message.
(CVE-2007-0898)

The update to 0.90 addresses these issues.

Affected: 2006.0, 2007.0, Corporate 3.0, Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2007:043

Risk factor : High

CVSS Score:
6.4

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2007-0897
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
BugTraq ID: 22580
http://www.securityfocus.com/bid/22580
Debian Security Information: DSA-1263 (Google Search)
http://www.debian.org/security/2007/dsa-1263
http://security.gentoo.org/glsa/glsa-200703-03.xml
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=475
http://www.mandriva.com/security/advisories?name=MDKSA-2007:043
http://osvdb.org/32283
http://www.securitytracker.com/id?1017659
http://secunia.com/advisories/24183
http://secunia.com/advisories/24187
http://secunia.com/advisories/24192
http://secunia.com/advisories/24319
http://secunia.com/advisories/24332
http://secunia.com/advisories/24425
http://secunia.com/advisories/29420
SuSE Security Announcement: SUSE-SA:2007:017 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.html
http://www.vupen.com/english/advisories/2007/0623
http://www.vupen.com/english/advisories/2008/0924/references
XForce ISS Database: clamav-cabfile-dos(32531)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32531
Common Vulnerability Exposure (CVE) ID: CVE-2007-0898
BugTraq ID: 22581
http://www.securityfocus.com/bid/22581
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=476
http://osvdb.org/32282
http://www.securitytracker.com/id?1017660
XForce ISS Database: clamav-mimeheader-directory-traversal(32535)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32535
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.