Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.131291
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia Linux Local Check: mgasa-2016-0161
Zusammenfassung:Mageia Linux Local Security Checks mgasa-2016-0161
Beschreibung:Summary:
Mageia Linux Local Security Checks mgasa-2016-0161

Vulnerability Insight:
Updated subversion packages fix security vulnerabilities: Daniel Shahaf and James McCoy discovered that an implementation error in the authentication against the Cyrus SASL library would permit a remote user to specify a realm string which is a prefix of the expected realm string and potentially allowing a user to authenticate using the wrong realm (CVE-2016-2167). Ivan Zhakov of VisualSVN discovered a remotely triggerable denial of service vulnerability in the mod_authz_svn module during COPY or MOVE authorization check. An authenticated remote attacker could take advantage of this flaw to cause a denial of service (Subversion server crash) via COPY or MOVE requests with specially crafted header (CVE-2016-2168).

Solution:
Update the affected packages to the latest available version.

CVSS Score:
4.9

CVSS Vector:
AV:N/AC:M/Au:S/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-2167
BugTraq ID: 89417
http://www.securityfocus.com/bid/89417
http://subversion.apache.org/security/CVE-2016-2167-advisory.txt
Debian Security Information: DSA-3561 (Google Search)
http://www.debian.org/security/2016/dsa-3561
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184545.html
https://security.gentoo.org/glsa/201610-05
https://www.oracle.com/security-alerts/cpuoct2020.html
http://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgJet+7_MAhomFVOXPgLtewcUw9w=k9zdPCkq5tvPxVMA@mail.gmail.com%3E
http://mail-archives.apache.org/mod_mbox/subversion-announce/201604.mbox/%3CCAP_GPNgfn1iKueW51EpmXzXi_URNfGNofZSgOyW1_jnSeNm5DQ@mail.gmail.com%3E
http://www.securitytracker.com/id/1035706
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.417496
SuSE Security Announcement: openSUSE-SU-2016:1263 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-05/msg00043.html
SuSE Security Announcement: openSUSE-SU-2016:1264 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-05/msg00044.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-2168
BugTraq ID: 89320
http://www.securityfocus.com/bid/89320
http://subversion.apache.org/security/CVE-2016-2168-advisory.txt
http://www.securitytracker.com/id/1035707
CopyrightCopyright (C) 2016 Eero Volotinen

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.