![]() |
Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | ||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.50770 |
Categoría: | Mandrake Local Security Checks |
Título: | Mandrake Security Advisory MDKSA-2003:114 (ethereal) |
Resumen: | NOSUMMARY |
Descripción: | Description: The remote host is missing an update to ethereal announced via advisory MDKSA-2003:114. A number of vulnerabilities were discovered in ethereal that, if exploited, could be used to make ethereal crash or run arbitrary code by injecting malicious malformed packets onto the wire or by convincing someone to read a malformed packet trace file. A buffer overflow allows attackers to cause a DoS (Denial of Service) and possibly execute arbitrary code using a malformed GTP MSISDN string (CVE-2003-0925). Likewise, a DoS can be caused by using malformed ISAKMP or MEGACO packets (CVE-2003-0926). Finally, a heap-based buffer overflow allows attackers to cause a DoS or execute arbitrary code using the SOCKS dissector (CVE-2003-0927). All three vulnerabilities affect all versions of Ethereal up to and including 0.9.15. This update provides 0.9.16 which corrects all of these issues. Also note that each vulnerability can be exploited by a remote attacker. Affected versions: 9.1, 9.2 Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2003:114 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0925 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0926 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0927 http://www.ethereal.com/appnotes/enpa-sa-00011.html Risk factor : High CVSS Score: 7.5 |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2003-0925 BugTraq ID: 8951 http://www.securityfocus.com/bid/8951 Conectiva Linux advisory: CLA-2003:780 http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000780 Debian Security Information: DSA-407 (Google Search) http://www.debian.org/security/2003/dsa-407 http://www.mandriva.com/security/advisories?name=MDKSA-2003:114 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9692 http://www.redhat.com/support/errata/RHSA-2003-323.html http://www.redhat.com/support/errata/RHSA-2003-324.html http://secunia.com/advisories/10531 TurboLinux Advisory: TLSA-2003-64 http://www.turbolinux.com/security/TLSA-2003-64.txt Common Vulnerability Exposure (CVE) ID: CVE-2003-0926 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11648 Common Vulnerability Exposure (CVE) ID: CVE-2003-0927 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9691 XForce ISS Database: ethereal-socks-heap-overflow(13578) https://exchange.xforce.ibmcloud.com/vulnerabilities/13578 |
Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |