Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.58085
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2007:043 (clamav)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to clamav
announced via advisory MDKSA-2007:043.

Clam AntiVirus ClamAV before 0.90 does not close open file descriptors
under certain conditions, which allows remote attackers to cause a
denial of service (file descriptor consumption and failed scans) via
CAB archives with a cabinet header record length of zero, which causes
a function to return without closing a file descriptor. (CVE-2007-0897)

Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV
before 0.90 allows remote attackers to overwrite arbitrary files via a
.. (dot dot) in the id MIME header parameter in a multi-part message.
(CVE-2007-0898)

The update to 0.90 addresses these issues.

Affected: 2006.0, 2007.0, Corporate 3.0, Corporate 4.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2007:043

Risk factor : High

CVSS Score:
6.4

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2007-0897
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
BugTraq ID: 22580
http://www.securityfocus.com/bid/22580
Debian Security Information: DSA-1263 (Google Search)
http://www.debian.org/security/2007/dsa-1263
http://security.gentoo.org/glsa/glsa-200703-03.xml
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=475
http://www.mandriva.com/security/advisories?name=MDKSA-2007:043
http://osvdb.org/32283
http://www.securitytracker.com/id?1017659
http://secunia.com/advisories/24183
http://secunia.com/advisories/24187
http://secunia.com/advisories/24192
http://secunia.com/advisories/24319
http://secunia.com/advisories/24332
http://secunia.com/advisories/24425
http://secunia.com/advisories/29420
SuSE Security Announcement: SUSE-SA:2007:017 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2007-Feb/0004.html
http://www.vupen.com/english/advisories/2007/0623
http://www.vupen.com/english/advisories/2008/0924/references
XForce ISS Database: clamav-cabfile-dos(32531)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32531
Common Vulnerability Exposure (CVE) ID: CVE-2007-0898
BugTraq ID: 22581
http://www.securityfocus.com/bid/22581
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=476
http://osvdb.org/32282
http://www.securitytracker.com/id?1017660
XForce ISS Database: clamav-mimeheader-directory-traversal(32535)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32535
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.