Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.56482
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2006:024 (ImageMagick)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to ImageMagick
announced via advisory MDKSA-2006:024.

The delegate code in ImageMagick 6.2.4.x allows remote attackers to
execute arbitrary commands via shell metacharacters in a filename that
is processed by the display command. (CVE-2005-4601)

A format string vulnerability in the SetImageInfo function in image.c for
ImageMagick 6.2.3, and other versions, allows user-complicit attackers
to cause a denial of service (crash) and possibly execute arbitrary
code via a numeric format string specifier such as %d in the file name,
a variant of CVE-2005-0397, and as demonstrated using the convert program.
(CVE-2006-0082)

The updated packages have been patched to correct these issues.

Affected: 2006.0, Corporate 3.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2006:024

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2005-4601
BugTraq ID: 16093
http://www.securityfocus.com/bid/16093
Bugtraq: 20061127 rPSA-2006-0218-1 ImageMagick (Google Search)
http://www.securityfocus.com/archive/1/452718/100/100/threaded
Debian Security Information: DSA-957 (Google Search)
http://www.debian.org/security/2006/dsa-957
http://www.mandriva.com/security/advisories?name=MDKSA-2006:024
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345238
http://www.osvdb.org/22121
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10353
RedHat Security Advisories: RHSA-2006:0178
http://rhn.redhat.com/errata/RHSA-2006-0178.html
http://secunia.com/advisories/18261
http://secunia.com/advisories/18607
http://secunia.com/advisories/18631
http://secunia.com/advisories/18871
http://secunia.com/advisories/19183
http://secunia.com/advisories/19408
http://secunia.com/advisories/23090
http://secunia.com/advisories/28800
SGI Security Advisory: 20060301-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.341682
http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1
SuSE Security Announcement: SUSE-SR:2006:006 (Google Search)
http://www.novell.com/linux/security/advisories/2006_06_sr.html
http://www.ubuntu.com/usn/usn-246-1
http://www.vupen.com/english/advisories/2008/0412
XForce ISS Database: imagemagick-filename-command-injection(23927)
https://exchange.xforce.ibmcloud.com/vulnerabilities/23927
Common Vulnerability Exposure (CVE) ID: CVE-2005-0397
20050303 [USN-90-1] Imagemagick vulnerability
http://marc.info/?l=bugtraq&m=110987256010857&w=2
DSA-702
http://www.debian.org/security/2005/dsa-702
GLSA-200503-11
http://www.gentoo.org/security/en/glsa/glsa-200503-11.xml
RHSA-2005:070
http://www.redhat.com/support/errata/RHSA-2005-070.html
RHSA-2005:320
http://www.redhat.com/support/errata/RHSA-2005-320.html
SUSE-SA:2005:017
http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html
http://bugs.gentoo.org/show_bug.cgi?id=83542
imagemagick-filename-format-string(19586)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19586
oval:org.mitre.oval:def:10302
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10302
Common Vulnerability Exposure (CVE) ID: CVE-2006-0082
BugTraq ID: 12717
http://www.securityfocus.com/bid/12717
Debian Security Information: DSA-1213 (Google Search)
http://www.debian.org/security/2006/dsa-1213
http://www.gentoo.org/security/en/glsa/glsa-200602-06.xml
http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10717
http://securitytracker.com/id?1015623
http://secunia.com/advisories/18851
http://secunia.com/advisories/19030
http://secunia.com/advisories/22998
http://securityreason.com/securityalert/500
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.