Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.51375
Kategorie:Conectiva Local Security Checks
Titel:Conectiva Security Advisory CLA-2004:882
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing updates announced in
advisory CLA-2004:882.

Squid[1] is a full-featured web proxy cache.

This announcement fixes a denial of service vulnerability[2] in squid
caused by a malformed NTLMSSP packet. This causes a negative value to
be passed to memcpy on servers with NTLM authentication enabled,
making squid abort and causing a denial of service condition.

Fixes for two segmentation faults were also included: when using a
blank user name in digest authentication[3] and after the message
Likely proxy abuse detected has been printed to cache.log[4].

Also fixes a denial of service situation[5] caused by certain
malformed SNMP requests that when received by squid could restart it
with a segmentation fault error.

For Conectiva Linux 9, this announcement also fixes a buffer overflow
vulnerability[6] in the ntlm_check_auth (NTLM authentication)
function that allowed remote attackers to execute arbitrary code via
a long password.


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://squid.nlanr.net/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0832
http://www1.uk.squid-cache.org/squid/Versions/v2/2.5/bugs/#squid-2.5.STABLE5-digest_blank
http://www1.uk.squid-cache.org/squid/Versions/v2/2.5/bugs/#squid-2.5.STABLE5-proxy_abuse
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0918
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0541
http://www.securityspace.com/smysecure/catid.html?in=CLA-2004:882
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002004

Risk factor : Critical

CVSS Score:
10.0

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2004-0832
BugTraq ID: 11098
http://www.securityfocus.com/bid/11098
http://fedoranews.org/updates/FEDORA--.shtml
http://www.gentoo.org/security/en/glsa/glsa-200409-04.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:093
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10489
http://www.trustix.org/errata/2004/0047/
XForce ISS Database: squid-ntlmssp-dos(17218)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17218
Common Vulnerability Exposure (CVE) ID: CVE-2004-0918
BugTraq ID: 11385
http://www.securityfocus.com/bid/11385
Conectiva Linux advisory: CLA-2005:923
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000923
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00122.html
http://www.gentoo.org/security/en/glsa/glsa-200410-15.xml
http://www.idefense.com/application/poi/display?id=152&type=vulnerabilities&flashstatus=false
http://marc.info/?l=bugtraq&m=109913064629327&w=2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10931
http://www.redhat.com/support/errata/RHSA-2004-591.html
SCO Security Bulletin: SCOSA-2005.16
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt
http://secunia.com/advisories/30914
http://secunia.com/advisories/30967
SuSE Security Announcement: SUSE-SR:2008:014 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html
http://www.vupen.com/english/advisories/2008/1969/references
XForce ISS Database: squid-snmp-asnparseheader-dos(17688)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17688
Common Vulnerability Exposure (CVE) ID: CVE-2004-0541
BugTraq ID: 10500
http://www.securityfocus.com/bid/10500
http://www.gentoo.org/security/en/glsa/glsa-200406-13.xml
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:059
http://www.idefense.com/application/poi/display?id=107&type=vulnerabilities
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10722
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A980
http://www.redhat.com/support/errata/RHSA-2004-242.html
SGI Security Advisory: 20040604-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040604-01-U.asc
SuSE Security Announcement: SuSE-SA:2004:016 (Google Search)
http://www.trustix.net/errata/2004/0033/
XForce ISS Database: squid-ntlm-bo(16360)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16360
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.