Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.120241
Kategorie:Amazon Linux Local Security Checks
Titel:Amazon Linux: Security Advisory (ALAS-2014-399)
Zusammenfassung:The remote host is missing an update for the 'glibc' package(s) announced via the ALAS-2014-399 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'glibc' package(s) announced via the ALAS-2014-399 advisory.

Vulnerability Insight:
An off-by-one heap-based buffer overflow flaw was found in glibc's internal __gconv_translit_find() function. An attacker able to make an application call the iconv_open() function with a specially crafted argument could possibly use this flaw to execute arbitrary code with the privileges of that application.

Affected Software/OS:
'glibc' package(s) on Amazon Linux.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-5119
20140826 CVE-2014-5119 glibc __gconv_translit_find() exploit
http://seclists.org/fulldisclosure/2014/Aug/69
20140910 Cisco Unified Communications Manager glibc Arbitrary Code Execution Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-5119
60345
http://secunia.com/advisories/60345
60358
http://secunia.com/advisories/60358
60441
http://secunia.com/advisories/60441
61074
http://secunia.com/advisories/61074
61093
http://secunia.com/advisories/61093
68983
http://www.securityfocus.com/bid/68983
69738
http://www.securityfocus.com/bid/69738
DSA-3012
http://www.debian.org/security/2014/dsa-3012
GLSA-201602-02
https://security.gentoo.org/glsa/201602-02
MDVSA-2014:175
http://www.mandriva.com/security/advisories?name=MDVSA-2014:175
RHSA-2014:1110
https://rhn.redhat.com/errata/RHSA-2014-1110.html
RHSA-2014:1118
http://rhn.redhat.com/errata/RHSA-2014-1118.html
SUSE-SU-2014:1125
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00017.html
[oss-security] 20170713 Re: [CVE Request] glibc iconv_open buffer overflow (was: Re: Re: glibc locale issues)
http://www.openwall.com/lists/oss-security/2014/08/13/5
[oss-security] 20170713 glibc locale issues
http://www.openwall.com/lists/oss-security/2014/07/14/1
http://googleprojectzero.blogspot.com/2014/08/the-poisoned-nul-byte-2014-edition.html
http://linux.oracle.com/errata/ELSA-2015-0092.html
http://www-01.ibm.com/support/docview.wss?uid=swg21685604
https://code.google.com/p/google-security-research/issues/detail?id=96
https://sourceware.org/bugzilla/show_bug.cgi?id=17187
CopyrightCopyright (C) 2015 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.