Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.55759
Kategorie:Mandrake Local Security Checks
Titel:Mandrake Security Advisory MDKSA-2005:193 (ethereal)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing an update to ethereal
announced via advisory MDKSA-2005:193.

Ethereal 0.10.13 is now available fixing a number of security
vulnerabilities in various dissectors:

- the ISAKMP dissector could exhaust system memory
- the FC-FCS dissector could exhaust system memory
- the RSVP dissector could exhaust system memory
- the ISIS LSP dissector could exhaust system memory
- the IrDA dissector could crash
- the SLIMP3 dissector could overflow a buffer
- the BER dissector was susceptible to an infinite loop
- the SCSI dissector could dereference a null pointer and crash
- the sFlow dissector could dereference a null pointer and crash
- the RTnet dissector could dereference a null pointer and crash
- the SigComp UDVM could go into an infinite loop or crash
- the X11 dissector could attempt to divide by zero
- if SMB transaction payload reassembly is enabled the SMB dissector
could crash (by default this is disabled)
- if the Dissect unknown RPC program numbers option was enabled, the
ONC RPC dissector might be able to exhaust system memory (by default
this is disabled)
- the AgentX dissector could overflow a buffer
- the WSP dissector could free an invalid pointer
- iDEFENSE discovered a buffer overflow in the SRVLOC dissector

The new version of Ethereal is provided and corrects all of these
issues.

Affected: 10.2, 2006.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2005:193
http://www.ethereal.com/appnotes/enpa-sa-00021.html

Risk factor : Critical

CVSS Score:
10.0

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2005-3241
1015082
http://securitytracker.com/id?1015082
15148
http://www.securityfocus.com/bid/15148
17254
http://secunia.com/advisories/17254
17286
http://secunia.com/advisories/17286
17327
http://secunia.com/advisories/17327
17377
http://secunia.com/advisories/17377
17392
http://secunia.com/advisories/17392
17480
http://secunia.com/advisories/17480
20121
http://www.osvdb.org/20121
20122
http://www.osvdb.org/20122
20123
http://www.osvdb.org/20123
20124
http://www.osvdb.org/20124
21813
http://secunia.com/advisories/21813
DSA-1171
http://www.debian.org/security/2006/dsa-1171
FLSA-2006:152922
http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html
GLSA-200510-25
http://www.gentoo.org/security/en/glsa/glsa-200510-25.xml
RHSA-2005:809
http://www.redhat.com/support/errata/RHSA-2005-809.html
SUSE-SR:2005:025
http://www.novell.com/linux/security/advisories/2005_25_sr.html
http://www.ethereal.com/appnotes/enpa-sa-00021.html
oval:org.mitre.oval:def:10582
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10582
Common Vulnerability Exposure (CVE) ID: CVE-2005-3242
20125
http://www.osvdb.org/20125
20133
http://www.osvdb.org/20133
oval:org.mitre.oval:def:10558
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10558
Common Vulnerability Exposure (CVE) ID: CVE-2005-3243
20126
http://www.osvdb.org/20126
20135
http://www.osvdb.org/20135
http://www.frsirt.com/exploits/20051020.ethereal_slimp3_bof.py.php
oval:org.mitre.oval:def:9836
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9836
Common Vulnerability Exposure (CVE) ID: CVE-2005-3244
20127
http://www.osvdb.org/20127
oval:org.mitre.oval:def:9665
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9665
Common Vulnerability Exposure (CVE) ID: CVE-2005-3245
20129
http://www.osvdb.org/20129
oval:org.mitre.oval:def:11060
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11060
Common Vulnerability Exposure (CVE) ID: CVE-2005-3246
20128
http://www.osvdb.org/20128
20130
http://www.osvdb.org/20130
20131
http://www.osvdb.org/20131
oval:org.mitre.oval:def:10303
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10303
Common Vulnerability Exposure (CVE) ID: CVE-2005-3247
20132
http://www.osvdb.org/20132
oval:org.mitre.oval:def:10241
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10241
Common Vulnerability Exposure (CVE) ID: CVE-2005-3248
20134
http://www.osvdb.org/20134
oval:org.mitre.oval:def:11002
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11002
Common Vulnerability Exposure (CVE) ID: CVE-2005-3249
20136
http://www.osvdb.org/20136
oval:org.mitre.oval:def:9313
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9313
Common Vulnerability Exposure (CVE) ID: CVE-2005-3184
BugTraq ID: 15148
BugTraq ID: 15158
http://www.securityfocus.com/bid/15158
http://www.idefense.com/application/poi/display?id=323&type=vulnerabilities
http://www.osvdb.org/20137
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10074
SuSE Security Announcement: SUSE-SR:2005:025 (Google Search)
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.