Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.881681
Kategorie:CentOS Local Security Checks
Titel:CentOS Update for emacs-git CESA-2013:0589 centos6
Zusammenfassung:The remote host is missing an update for the 'emacs-git'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'emacs-git'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Git is a fast, scalable, distributed revision control system.

It was discovered that Git's git-imap-send command, a tool to send a
collection of patches from standard input (stdin) to an IMAP folder, did
not properly perform SSL X.509 v3 certificate validation on the IMAP
server's certificate, as it did not ensure that the server's hostname
matched the one provided in the CN field of the server's certificate. A
rogue server could use this flaw to conduct man-in-the-middle attacks,
possibly leading to the disclosure of sensitive information.
(CVE-2013-0308)

All git users should upgrade to these updated packages, which contain a
backported patch to correct this issue.

Affected Software/OS:
emacs-git on CentOS 6

Solution:
Please install the updated packages.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-0308
http://lists.apple.com/archives/security-announce/2013/Sep/msg00007.html
BugTraq ID: 58148
http://www.securityfocus.com/bid/58148
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=701586
https://bugzilla.novell.com/show_bug.cgi?id=804730
https://bugzilla.redhat.com/show_bug.cgi?id=909977
http://marc.info/?l=git&m=136134619013145&w=2
RedHat Security Advisories: RHSA-2013:0589
http://rhn.redhat.com/errata/RHSA-2013-0589.html
http://www.securitytracker.com/id/1028205
http://secunia.com/advisories/52361
http://secunia.com/advisories/52443
http://secunia.com/advisories/52467
SuSE Security Announcement: openSUSE-SU-2013:0380 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-03/msg00005.html
SuSE Security Announcement: openSUSE-SU-2013:0382 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-03/msg00007.html
XForce ISS Database: git-gitimapsend-spoofing(82329)
https://exchange.xforce.ibmcloud.com/vulnerabilities/82329
CopyrightCopyright (c) 2013 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.