Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.881540
Kategorie:CentOS Local Security Checks
Titel:CentOS Update for gegl CESA-2012:1455 centos6
Zusammenfassung:The remote host is missing an update for the 'gegl'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'gegl'
package(s) announced via the referenced advisory.

Vulnerability Insight:
GEGL (Generic Graphics Library) is a graph-based image processing
framework.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the gegl utility processed .ppm (Portable Pixel Map) image
files. An attacker could create a specially-crafted .ppm file that, when
opened in gegl, would cause gegl to crash or, potentially, execute
arbitrary code. (CVE-2012-4433)

This issue was discovered by Murray McAllister of the Red Hat Security
Response Team.

Users of gegl should upgrade to these updated packages, which contain a
backported patch to correct this issue.

Affected Software/OS:
gegl on CentOS 6

Solution:
Please install the updated packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2012-4433
1027754
http://www.securitytracker.com/id?1027754
51114
http://secunia.com/advisories/51114
51274
http://secunia.com/advisories/51274
56404
http://www.securityfocus.com/bid/56404
MDVSA-2013:081
http://www.mandriva.com/security/advisories?name=MDVSA-2013:081
RHSA-2012:1455
http://rhn.redhat.com/errata/RHSA-2012-1455.html
[oss-security] 20121106 gegl: Integer overflow, leading to heap-based buffer overflow by parsing PPM image headers
http://www.openwall.com/lists/oss-security/2012/11/06/1
gegl-ppm-bo(79822)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79822
http://git.gnome.org/browse/gegl/commit/?id=1e92e5235ded0415d555aa86066b8e4041ee5a53
http://git.gnome.org/browse/gegl/commit/?id=4757cdf73d3675478d645a3ec8250ba02168a230
https://bugzilla.redhat.com/show_bug.cgi?id=856300
openSUSE-SU-2013:0159
http://lists.opensuse.org/opensuse-updates/2013-01/msg00054.html
CopyrightCopyright (C) 2012 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.