Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.10833
Kategorie:Gain root remotely
Titel:dtspcd overflow
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The 'dtspcd' service is running. This service deals with
the CDE interface for the X11 system.

Some versions of this daemon are vulnerable to a buffer overflow
attack which may allow an attacker to gain root privileges on
this host.

*** This warning might be a false positive,
*** as no real overflow was performed

Solution : See http://www.cert.org/advisories/CA-2001-31.html
to determine if you are vulnerable or deactivate this service
(comment out the line 'dtspc' in /etc/inetd.conf and restart the inetd process)

Risk factor : High

Querverweis: BugTraq ID: 3517
Common Vulnerability Exposure (CVE) ID: CVE-2001-0803
http://www.securityfocus.com/bid/3517
Caldera Security Advisory: CSSA-2001-SCO.30
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/
http://www.cert.org/advisories/CA-2001-31.html
http://www.cert.org/advisories/CA-2002-01.html
CERT/CC vulnerability note: VU#172583
http://www.kb.cert.org/vuls/id/172583
COMPAQ Service Security Patch: SSRT541
http://ftp.support.compaq.com/patches/.new/html/SSRT-541.shtml
HPdes Security Advisory: HPSBUX0111-175
http://www.securityfocus.com/advisories/3651
ISS Security Advisory: 20011112 Multi-Vendor Buffer Overflow Vulnerability in CDE Subprocess Control Service
http://xforce.iss.net/alerts/advise101.php
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A70
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A74
SGI Security Advisory: 20011107-01-P
ftp://patches.sgi.com/support/free/security/advisories/20011107-01-P
Sun Security Bulletin: 00214
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/214
XForce ISS Database: cde-dtspcd-bo(7396)
https://exchange.xforce.ibmcloud.com/vulnerabilities/7396
CopyrightThis script is Copyright (C) 2002 Renaud Deraison

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.