Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.703654
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 3654-1 (quagga - security update)
Zusammenfassung:Two vulnerabilities were discovered;in quagga, a BGP/OSPF/RIP routing daemon.;;CVE-2016-4036;Tams Nmeth discovered that sensitive configuration files in;/etc/quagga were world-readable despite containing sensitive;information.;;CVE-2016-4049;Evgeny Uskov discovered that a bgpd instance handling many peers;could be crashed by a malicious user when requesting a route dump.
Beschreibung:Summary:
Two vulnerabilities were discovered
in quagga, a BGP/OSPF/RIP routing daemon.

CVE-2016-4036
Tams Nmeth discovered that sensitive configuration files in
/etc/quagga were world-readable despite containing sensitive
information.

CVE-2016-4049
Evgeny Uskov discovered that a bgpd instance handling many peers
could be crashed by a malicious user when requesting a route dump.

Affected Software/OS:
quagga on Debian Linux

Solution:
For the stable distribution (jessie),
these problems have been fixed in version 0.99.23.1-1+deb8u2.

We recommend that you upgrade your quagga packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-4036
BugTraq ID: 87324
http://www.securityfocus.com/bid/87324
Debian Security Information: DSA-3654 (Google Search)
http://www.debian.org/security/2016/dsa-3654
SuSE Security Announcement: openSUSE-SU-2016:1030 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-04/msg00040.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-4049
BugTraq ID: 88561
http://www.securityfocus.com/bid/88561
https://security.gentoo.org/glsa/201701-48
http://www.openwall.com/lists/oss-security/2016/04/27/7
https://lists.quagga.net/pipermail/quagga-dev/2016-January/014699.html
https://lists.quagga.net/pipermail/quagga-dev/2016-February/014743.html
RedHat Security Advisories: RHSA-2017:0794
http://rhn.redhat.com/errata/RHSA-2017-0794.html
http://www.securitytracker.com/id/1035699
SuSE Security Announcement: openSUSE-SU-2016:1313 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-05/msg00062.html
CopyrightCopyright (c) 2016 Greenbone Networks GmbH http://greenbone.net

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.