Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.58171
Kategorie:Mandrake Local Security Checks
Titel:Mandrake Security Advisory MDKSA-2007:071 (xmms)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing an update to xmms
announced via advisory MDKSA-2007:071.

Integer overflow in X MultiMedia System (xmms) 1.2.10, and possibly
other versions, allows user-assisted remote attackers to execute
arbitrary code via crafted header information in a skin bitmap image,
which triggers memory corruption. (CVE-2007-0653)

Integer underflow in X MultiMedia System (xmms) 1.2.10 allows
user-assisted remote attackers to execute arbitrary code via crafted
header information in a skin bitmap image, which results in a stack-
based buffer overflow. (CVE-2007-0654)

Updated packages have been patched to correct these issues.

Affected: Corporate 3.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2007:071

Risk factor : Critical

CVSS Score:
9.3

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2007-0653
BugTraq ID: 23078
http://www.securityfocus.com/bid/23078
Bugtraq: 20070321 Secunia Research: XMMS Integer Overflow and UnderflowVulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/463408/100/0/threaded
Debian Security Information: DSA-1277 (Google Search)
http://www.debian.org/security/2007/dsa-1277
http://www.mandriva.com/security/advisories?name=MDKSA-2007:071
http://secunia.com/secunia_research/2007-47/advisory/
http://secunia.com/advisories/23986
http://secunia.com/advisories/24645
http://secunia.com/advisories/24804
http://secunia.com/advisories/24889
SuSE Security Announcement: SUSE-SR:2007:006 (Google Search)
http://www.novell.com/linux/security/advisories/2007_6_sr.html
http://www.ubuntu.com/usn/usn-445-1
http://www.vupen.com/english/advisories/2007/1057
XForce ISS Database: xmms-skinbitmap-code-execution(33205)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33205
Common Vulnerability Exposure (CVE) ID: CVE-2007-0654
XForce ISS Database: xmms-skinbitmap-bo(33203)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33203
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.