Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.703599
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 3599-1 (p7zip - security update)
Zusammenfassung:Marcin Icewall;Noga of Cisco Talos discovered an out-of-bound read;vulnerability in the CInArchive::ReadFileItem method in p7zip, a 7zr;file archiver with high compression ratio. A remote attacker can take;advantage of this flaw to cause a denial-of-service or, potentially the;execution of arbitrary code with the privileges of the user running;p7zip, if a specially crafted UDF file is processed.
Beschreibung:Summary:
Marcin Icewall
Noga of Cisco Talos discovered an out-of-bound read
vulnerability in the CInArchive::ReadFileItem method in p7zip, a 7zr
file archiver with high compression ratio. A remote attacker can take
advantage of this flaw to cause a denial-of-service or, potentially the
execution of arbitrary code with the privileges of the user running
p7zip, if a specially crafted UDF file is processed.

Affected Software/OS:
p7zip on Debian Linux

Solution:
For the stable distribution (jessie),
this problem has been fixed in version 9.20.1~
dfsg.1-4.1+deb8u2.

For the testing distribution (stretch), this problem has been fixed
in version 15.14.1+dfsg-2.

For the unstable distribution (sid), this problem has been fixed in
version 15.14.1+dfsg-2.

We recommend that you upgrade your p7zip packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-2335
BugTraq ID: 90531
http://www.securityfocus.com/bid/90531
Debian Security Information: DSA-3599 (Google Search)
http://www.debian.org/security/2016/dsa-3599
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DNYIQAU3FKFBNFPK6GKYTSVRHQA7PTYT/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DTGWICT3KYYDPDXRNO5SXD32GZICGRIR/
https://security.gentoo.org/glsa/201701-27
http://blog.talosintel.com/2016/05/multiple-7-zip-vulnerabilities.html
http://www.talosintel.com/reports/TALOS-2016-0094/
http://www.securitytracker.com/id/1035876
SuSE Security Announcement: openSUSE-SU-2016:1464 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-06/msg00004.html
SuSE Security Announcement: openSUSE-SU-2016:1675 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-06/msg00098.html
SuSE Security Announcement: openSUSE-SU-2016:1850 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-07/msg00069.html
https://usn.ubuntu.com/3913-1/
CopyrightCopyright (c) 2016 Greenbone Networks GmbH http://greenbone.net

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.