Anfälligkeitssuche        Suche in 211766 CVE Beschreibungen
und 97459 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.4.2018.2934.1
Kategorie:SuSE Local Security Checks
Titel:SUSE: Security Advisory (SUSE-SU-2018:2934-1)
Zusammenfassung:The remote host is missing an update for the 'xorg-x11-libX11' package(s) announced via the SUSE-SU-2018:2934-1 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'xorg-x11-libX11' package(s) announced via the SUSE-SU-2018:2934-1 advisory.

Vulnerability Insight:
This update for xorg-x11-libX11 fixes the following issues:
CVE-2018-14599: The function XListExtensions was vulnerable to an
off-by-one error caused by malicious server responses, leading to DoS or
possibly unspecified other impact (bsc#1102062)

CVE-2018-14600: The function XListExtensions interpreted a variable as
signed instead of unsigned, resulting in an out-of-bounds write (of up
to 128 bytes), leading to DoS or remote code execution (bsc#1102068)

CVE-2018-14598: A malicious server could have sent a reply in which the
first string overflows, causing a variable to be set to NULL that will
be freed later
on, leading to DoS (segmentation fault) (bsc#1102073)

Affected Software/OS:
'xorg-x11-libX11' package(s) on SUSE Linux Enterprise Software Development Kit 11-SP4, SUSE Linux Enterprise Server 11-SP4, SUSE Linux Enterprise Server 11-SP3, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Debuginfo 11-SP3

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2018-14598
Common Vulnerability Exposure (CVE) ID: CVE-2018-14599
Common Vulnerability Exposure (CVE) ID: CVE-2018-14600
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

Dies ist nur einer von 97459 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2021 E-Soft Inc. Alle Rechte vorbehalten.