Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.52401
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: krb5
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: krb5

CVE-2004-0642
Double-free vulnerabilities in the error handling code for ASN.1
decoders in the (1) Key Distribution Center (KDC) library and (2)
client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow
remote attackers to execute arbitrary code.

CVE-2004-0643
Double-free vulnerability in the krb5_rd_cred function for MIT
Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute
arbitrary code.

CVE-2004-0772
Double-free vulnerabilities in error handling code in krb524d for MIT
Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to
execute arbitrary code.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2004-0642
BugTraq ID: 11078
http://www.securityfocus.com/bid/11078
Bugtraq: 20040913 [OpenPKG-SA-2004.039] OpenPKG Security Advisory (kerberos) (Google Search)
http://marc.info/?l=bugtraq&m=109508872524753&w=2
Cert/CC Advisory: TA04-247A
http://www.us-cert.gov/cas/techalerts/TA04-247A.html
CERT/CC vulnerability note: VU#795632
http://www.kb.cert.org/vuls/id/795632
Conectiva Linux advisory: CLA-2004:860
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000860
Debian Security Information: DSA-543 (Google Search)
http://www.debian.org/security/2004/dsa-543
http://www.gentoo.org/security/en/glsa/glsa-200409-09.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10709
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4936
RedHat Security Advisories: RHSA-2004:350
http://rhn.redhat.com/errata/RHSA-2004-350.html
http://www.trustix.net/errata/2004/0045/
XForce ISS Database: kerberos-kdc-double-free(17157)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17157
Common Vulnerability Exposure (CVE) ID: CVE-2004-0643
CERT/CC vulnerability note: VU#866472
http://www.kb.cert.org/vuls/id/866472
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10267
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3322
XForce ISS Database: kerberos-krb5rdcred-double-free(17159)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17159
Common Vulnerability Exposure (CVE) ID: CVE-2004-0772
CERT/CC vulnerability note: VU#350792
http://www.kb.cert.org/vuls/id/350792
http://www.mandriva.com/security/advisories?name=MDKSA-2004:088
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4661
XForce ISS Database: kerberos-krb524d-double-free(17158)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17158
CopyrightCopyright (C) 2008 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.