Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.63932
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 1779-1 (apt)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to apt
announced via advisory DSA 1779-1.

Two vulnerabilities have been discovered in APT, the well-known dpkg
frontend. The Common Vulnerabilities and Exposures project identifies
the following problems:

CVE-2009-1300

In time zones where daylight savings time occurs at midnight,
the apt cron.daily script fails, stopping new security updates
from being applied automatically.

CVE-2009-1358

A repository that has been signed with an expired or revoked
OpenPGP key would still be considered valid by APT.

For the old stable distribution (etch), these problems have been fixed in
version 0.6.46.4-0.1+etch1.

For the stable distribution (lenny), these problems have been fixed in
version 0.7.20.2+lenny1.

For the unstable distribution (sid), these problems have been fixed in
version 0.7.21.

We recommend that you upgrade your apt package.

Solution:
http://www.securityspace.com/smysecure/catid.html?in=DSA%201779-1

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-1300
Debian Security Information: DSA-1779 (Google Search)
http://www.debian.org/security/2009/dsa-1779
http://www.openwall.com/lists/oss-security/2009/04/08/11
http://secunia.com/advisories/34829
http://secunia.com/advisories/34832
http://secunia.com/advisories/34874
https://usn.ubuntu.com/762-1/
Common Vulnerability Exposure (CVE) ID: CVE-2009-1358
BugTraq ID: 34630
http://www.securityfocus.com/bid/34630
XForce ISS Database: apt-aptget-gpgv-security-bypass(50086)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50086
CopyrightCopyright (c) 2009 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.