Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.50848
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2002:075 (nss_ldap)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to nss_ldap
announced via advisory MDKSA-2002:075.

A buffer overflow vulnerability exists in nss_ldap versions prior to
198. When nss_ldap is configured without a value for the host
keyword, it attempts to configure itself using SRV records stored in
DNS. nss_ldap does not check that the data returned by the DNS query
will fit into an internal buffer, thus exposing it to an overflow.

A similar issue exists in versions of nss_ldap prior to 199 where
nss_ldap does not check that the data returned by the DNS query has not
been truncated by the resolver libraries to avoid a buffer overflow.
This can make nss_ldap attempt to parse more data than what is actually
available, making it vulnerable to a read buffer overflow.

Finally, a format string bug in the logging function of pam_ldap prior
to version 144 exist.

All users are recommended to upgrade to these updated packages. Note
that the nss_ldap packages for 7.2, 8.0, and Single Network Firewall
7.2 contain the pam_ldap modules.

Affected versions: 7.2, 8.0, 8.1, 8.2, 9.0,
Single Network Firewall 7.2


Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2002:075
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0825
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0374
http://www.kb.cert.org/vuls/id/738331
http://www.padl.com/Articles/PotentialBufferOverflowin.html

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2002-0825
Common Vulnerability Exposure (CVE) ID: CVE-2002-0374
BugTraq ID: 4679
http://www.securityfocus.com/bid/4679
Bugtraq: 20020506 ldap vulnerabilities (Google Search)
Bugtraq: 20021030 GLSA: pam_ldap (Google Search)
http://marc.info/?l=bugtraq&m=103601912505261&w=2
Caldera Security Advisory: CSSA-2002-041.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-041.0.txt
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:075
http://www.redhat.com/support/errata/RHSA-2002-084.html
http://www.redhat.com/support/errata/RHSA-2002-141.html
http://www.redhat.com/support/errata/RHSA-2002-175.html
http://www.redhat.com/support/errata/RHSA-2002-180.html
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0053.html
http://www.iss.net/security_center/static/9018.php
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.