Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.56494
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2006:057 (cairo)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to cairo
announced via advisory MDKSA-2006:057.

GNOME Evolution allows remote attackers to cause a denial of service
(persistent client crash) via an attached text file that contains
Content-Disposition: inline in the header, and a very long line in
the body, which causes the client to repeatedly crash until the e-mail
message is manually removed, possibly due to a buffer overflow, as
demonstrated using an XML attachment.

The underlying issue is in libcairo, which is used by recent versions
of Evolution for message rendering.

The Corporate Desktop 3.0 version of Evolution does not use libcairo
and is not vulnerable to this issue.

Updated packages have been patched to correct these issues.

Affected: 2006.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2006:057

Risk factor : Medium

CVSS Score:
5.0

Referencia Cruzada: BugTraq ID: 16408
Common Vulnerability Exposure (CVE) ID: CVE-2006-0528
http://www.securityfocus.com/bid/16408
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0925.html
http://www.mandriva.com/security/advisories?name=MDKSA-2006:057
http://secunia.com/advisories/19504
http://securityreason.com/securityalert/610
SuSE Security Announcement: SUSE-SR:2006:007 (Google Search)
http://www.novell.com/linux/security/advisories/2006_07_sr.html
https://usn.ubuntu.com/265-1/
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.