Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.50602
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2004:120 (mpg123)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to mpg123
announced via advisory MDKSA-2004:120.

Carlos Barros discovered two buffer overflow vulnerabilities in mpg123

the first in the getauthfromURL() function and the second in the
http_open() function. These vulnerabilities could be exploited to
possibly execute arbitrary code with the privileges of the user running
mpg123.

The provided packages are patched to fix these issues, as well
additional boundary checks that were lacking have been included (thanks
to the Gentoo Linux Sound Team for these additional fixes).

Affected versions: 10.0, 10.1, Corporate Server 2.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2004:120
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0891
http://www.barrossecurity.com/advisories/mpg123_getauthfromurl_bof_advisory.txt

Risk factor : Critical

CVSS Score:
10.0

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2004-0891
https://bugzilla.fedora.us/show_bug.cgi?id=2188
http://www.gentoo.org/security/en/glsa/glsa-200410-23.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11790
http://www.redhat.com/support/errata/RHSA-2004-604.html
https://www.ubuntu.com/usn/usn-8-1/
XForce ISS Database: gaim-file-transfer-dos(17790)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17790
XForce ISS Database: gaim-msn-slp-bo(17786)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17786
XForce ISS Database: gaim-msn-slp-dos(17787)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17787
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.