Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.67286
Kategorie:Ubuntu Local Security Checks
Titel:Ubuntu USN-929-1 (irssi)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to irssi
announced via advisory USN-929-1.

Details follow:

It was discovered that irssi did not perform certificate host validation
when using SSL connections. An attacker could exploit this to perform a man
in the middle attack to view sensitive information or alter encrypted
communications. (CVE-2010-1155)

Aurelien Delaitre discovered that irssi could be made to dereference a NULL
pointer when a user left the channel. A remote attacker could cause a
denial of service via application crash. (CVE-2010-1156)

This update also adds SSLv3 and TLSv1 support, while disabling the old,
insecure SSLv2 protocol.

Solution:
The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.04 LTS:
irssi 0.8.12-3ubuntu3.2

Ubuntu 8.10:
irssi 0.8.12-4ubuntu2.2

Ubuntu 9.04:
irssi 0.8.12-6ubuntu1.2

Ubuntu 9.10:
irssi 0.8.14-1ubuntu1.1

After a standard system upgrade you need to restart irssi to effect the
necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-929-1

Risk factor : High

CVSS Score:
6.8

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-1155
http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041054.html
http://marc.info/?l=oss-security&m=127098845125270&w=2
http://marc.info/?l=oss-security&m=127110132019166&w=2
http://marc.info/?l=oss-security&m=127116251220784&w=2
http://marc.info/?l=oss-security&m=127119240204394&w=2
http://secunia.com/advisories/39365
http://secunia.com/advisories/39620
http://secunia.com/advisories/39797
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.497301
SuSE Security Announcement: SUSE-SR:2010:011 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html
http://www.ubuntu.com/usn/USN-929-1
http://www.vupen.com/english/advisories/2010/0856
http://www.vupen.com/english/advisories/2010/0987
http://www.vupen.com/english/advisories/2010/1107
http://www.vupen.com/english/advisories/2010/1110
XForce ISS Database: irssi-hostname-mitm(57790)
https://exchange.xforce.ibmcloud.com/vulnerabilities/57790
Common Vulnerability Exposure (CVE) ID: CVE-2010-1156
http://marc.info/?l=oss-security&m=127111071631857&w=2
http://marc.info/?l=oss-security&m=127115784314970&w=2
http://securitytracker.com/id?1023845
XForce ISS Database: irssi-unspecified-dos(57791)
https://exchange.xforce.ibmcloud.com/vulnerabilities/57791
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.