Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.50545
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2004:063 (libpng)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to libpng
announced via advisory MDKSA-2004:063.

A buffer overflow vulnerability was discovered in libpng due to a wrong
calculation of some loop offset values. This buffer overflow can lead
to Denial of Service or even remote compromise.

This vulnerability was initially patched in January of 2003, but it
has since been noted that fixes were required in two additional places
that had not been corrected with the earlier patch. This update uses
an updated patch to fix all known issues.

After the upgrade, all applications that use libpng should be
restarted. Many applications are linked to libpng, so if you are
unsure of what applications to restart, you may wish to reboot the
system. Mandrakesoft encourages all users to upgrade immediately.

Affected versions: 10.0, 9.1, 9.2, Corporate Server 2.1,
Multi Network Firewall 8.2


Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2004:063
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1363
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:008

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: BugTraq ID: 6431
Common Vulnerability Exposure (CVE) ID: CVE-2002-1363
http://www.securityfocus.com/bid/6431
Debian Security Information: DSA-213 (Google Search)
http://www.debian.org/security/2002/dsa-213
https://bugzilla.fedora.us/show_bug.cgi?id=1943
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2003:008
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:063
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3657
http://www.redhat.com/support/errata/RHSA-2003-006.html
http://www.redhat.com/support/errata/RHSA-2003-007.html
http://www.redhat.com/support/errata/RHSA-2003-119.html
http://www.redhat.com/support/errata/RHSA-2003-157.html
http://www.redhat.com/support/errata/RHSA-2004-249.html
http://www.redhat.com/support/errata/RHSA-2004-402.html
SuSE Security Announcement: SUSE-SA:2003:0004 (Google Search)
http://www.novell.com/linux/security/advisories/2003_004_libpng.html
XForce ISS Database: libpng-file-offset-bo(10925)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10925
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.