Búsqueda de    
Vulnerabilidad   
    Buscar 211766 Descripciones CVE y
97459 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.4.2012.0393.1
Categoría:SuSE Local Security Checks
Título:SUSE: Security Advisory (SUSE-SU-2012:0393-1)
Resumen:The remote host is missing an update for the 'Mono' package(s) announced via the SUSE-SU-2012:0393-1 advisory.
Descripción:Summary:
The remote host is missing an update for the 'Mono' package(s) announced via the SUSE-SU-2012:0393-1 advisory.

Vulnerability Insight:
The FORMS authentication methods of mono ASP.net implementation were vulnerable to a padding oracle attack as described in CVE-2010-3332, as they did encryption after checksum.

This update changes the method to checksum after encryption to avoid this attack.

Security Issue reference:

* CVE-2010-3332
>

Affected Software/OS:
'Mono' package(s) on SUSE Linux Enterprise Server 10 SP4, SUSE Linux Enterprise Desktop 10 SP4, SLE SDK 10 SP4

Solution:
Please install the updated package(s).

CVSS Score:
6.4

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-3332
BugTraq ID: 43316
http://www.securityfocus.com/bid/43316
http://isc.sans.edu/diary.html?storyid=9568
http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/
http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310
http://twitter.com/thaidn/statuses/24832350146
http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspx
http://www.ekoparty.org/juliano-rizzo-2010.php
http://www.theinquirer.net/inquirer/news/1732956/security-researchers-destroy-microsoft-aspnet-security
http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.html
Microsoft Security Bulletin: MS10-070
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12365
http://securitytracker.com/id?1024459
http://secunia.com/advisories/41409
http://www.vupen.com/english/advisories/2010/2429
http://www.vupen.com/english/advisories/2010/2751
XForce ISS Database: ms-aspdotnet-padding-info-disclosure(61898)
https://exchange.xforce.ibmcloud.com/vulnerabilities/61898
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

Esta es sólo una de 97459 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2021 E-Soft Inc. Todos los derechos reservados.