Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.2.2019.2472
Kategorie:Huawei EulerOS Local Security Checks
Titel:Huawei EulerOS: Security Advisory for libsrtp (EulerOS-SA-2019-2472)
Zusammenfassung:The remote host is missing an update for the Huawei EulerOS 'libsrtp' package(s) announced via the EulerOS-SA-2019-2472 advisory.
Beschreibung:Summary:
The remote host is missing an update for the Huawei EulerOS 'libsrtp' package(s) announced via the EulerOS-SA-2019-2472 advisory.

Vulnerability Insight:
Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and srtp_protect functions.(CVE-2013-2139)

The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.(CVE-2015-6360)

Affected Software/OS:
'libsrtp' package(s) on Huawei EulerOS V2.0SP2.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-2139
Debian Security Information: DSA-2840 (Google Search)
http://www.debian.org/security/2014/dsa-2840
http://lwn.net/Articles/579633/
http://seclists.org/fulldisclosure/2013/Jun/10
http://www.mandriva.com/security/advisories?name=MDVSA-2014:219
http://www.osvdb.org/93852
SuSE Security Announcement: openSUSE-SU-2013:1258 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-07/msg00083.html
SuSE Security Announcement: openSUSE-SU-2014:1250 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-09/msg00059.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-6360
Cisco Security Advisory: 20160420 Multiple Cisco Products libSRTP Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160420-libsrtp
Debian Security Information: DSA-3539 (Google Search)
http://www.debian.org/security/2016/dsa-3539
http://www.securitytracker.com/id/1035636
http://www.securitytracker.com/id/1035637
http://www.securitytracker.com/id/1035648
http://www.securitytracker.com/id/1035649
http://www.securitytracker.com/id/1035650
http://www.securitytracker.com/id/1035651
http://www.securitytracker.com/id/1035652
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.