Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.800422
Kategorie:General
Titel:Pidgin MSN Custom Smileys File Disclosure Vulnerability (Linux)
Zusammenfassung:This host has Pidgin installed and is prone to File Disclosure; vulnerability
Beschreibung:Summary:
This host has Pidgin installed and is prone to File Disclosure
vulnerability

Vulnerability Insight:
This issue is due to an error in 'slp.c' within the 'MSN protocol plugin'
in 'libpurple' when processing application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request.

Vulnerability Impact:
Attackers can exploit this issue to gain knowledge of sensitive information
via directory traversal attacks.

Affected Software/OS:
Pidgin version prior to 2.6.4 on Linux.

Solution:
Apply the patch or upgrade to Pidgin version 2.6.5.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-0013
http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033771.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033848.html
http://www.mandriva.com/security/advisories?name=MDVSA-2010:085
http://d.pidgin.im/viewmtn/revision/info/3d02401cf232459fc80c0837d31e05fae7ae5467
http://d.pidgin.im/viewmtn/revision/info/4be2df4f72bd8a55cdae7f2554b73342a497c92f
http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html
http://www.openwall.com/lists/oss-security/2010/01/02/1
http://www.openwall.com/lists/oss-security/2010/01/07/1
http://www.openwall.com/lists/oss-security/2010/01/07/2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10333
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17620
http://secunia.com/advisories/37953
http://secunia.com/advisories/37954
http://secunia.com/advisories/37961
http://secunia.com/advisories/38915
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022203.1-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-277450-1
SuSE Security Announcement: SUSE-SR:2010:006 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html
http://www.vupen.com/english/advisories/2009/3662
http://www.vupen.com/english/advisories/2009/3663
http://www.vupen.com/english/advisories/2010/1020
CopyrightCopyright (c) 2010 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.