Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.703309
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 3309-1 (tidy - security update)
Zusammenfassung:Fernando Muoz discovered that invalid HTML input passed to tidy, an;HTML syntax checker and reformatter, could trigger a buffer overflow.;This could allow remote attackers to cause a denial of service (crash);or potentially execute arbitrary code.;;Geoff McLane also discovered that a similar issue could trigger an;integer overflow, leading to a memory allocation of 4GB. This could;allow remote attackers to cause a denial of service by saturating the;target's memory.
Beschreibung:Summary:
Fernando Muoz discovered that invalid HTML input passed to tidy, an
HTML syntax checker and reformatter, could trigger a buffer overflow.
This could allow remote attackers to cause a denial of service (crash)
or potentially execute arbitrary code.

Geoff McLane also discovered that a similar issue could trigger an
integer overflow, leading to a memory allocation of 4GB. This could
allow remote attackers to cause a denial of service by saturating the
target's memory.

Affected Software/OS:
tidy on Debian Linux

Solution:
For the oldstable distribution (wheezy), these problems have been fixed
in version 20091223cvs-1.2+deb7u1.

For the stable distribution (jessie), these problems have been fixed in
version 20091223cvs-1.4+deb8u1.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your tidy packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2015-5522
http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html
http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.html
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html
BugTraq ID: 75037
http://www.securityfocus.com/bid/75037
Debian Security Information: DSA-3309 (Google Search)
http://www.debian.org/security/2015/dsa-3309
http://www.openwall.com/lists/oss-security/2015/06/04/2
http://www.openwall.com/lists/oss-security/2015/07/13/7
http://www.openwall.com/lists/oss-security/2015/07/15/3
http://www.securitytracker.com/id/1033703
http://www.ubuntu.com/usn/USN-2695-1
Common Vulnerability Exposure (CVE) ID: CVE-2015-5523
CopyrightCopyright (c) 2015 Greenbone Networks GmbH http://greenbone.net

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.