Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.56337
Kategorie:Ubuntu Local Security Checks
Titel:Ubuntu USN-256-1 (bluez-hcidump)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing an update to bluez-hcidump
announced via advisory USN-256-1.

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)

The following packages are affected: bluez-hcidump

Pierre Betouin discovered a Denial of Service vulnerability in the
handling of the L2CAP (Logical Link Control and Adaptation Layer
Protocol) layer. By sending a specially crafted L2CAP packet through a
wireless Bluetooth connection, a remote attacker could crash hcidump.

Since hcidump is mainly a debugging tool, the impact of this flaw is
very low.

Solution:
The problem can be corrected by upgrading the affected package to
version 1.5-2ubuntu0.1 (for Ubuntu 4.10), 1.12-1ubuntu0.1 (for Ubuntu
5.04), or 1.23-0ubuntu1.1 (for Ubuntu 5.10). In general, a standard
system upgrade is sufficient to effect the necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-256-1

Risk factor : Medium

CVSS Score:
5.0

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2006-0670
Bugtraq: 20060206 [ Secuobs - Advisory ] Bluetooth : DoS on hcidump 1.29 + PoC (Google Search)
http://www.securityfocus.com/archive/1/424133/100/0/threaded
Debian Security Information: DSA-990 (Google Search)
http://www.debian.org/security/2006/dsa-990
http://marc.info/?l=full-disclosure&m=113924625825488&w=2
http://www.mandriva.com/security/advisories?name=MDKSA-2006:041
http://www.secuobs.com/news/05022006-bluetooth9.shtml#english
http://www.osvdb.org/23056
http://secunia.com/advisories/18741
http://secunia.com/advisories/18971
http://secunia.com/advisories/19122
http://securityreason.com/securityalert/465
http://www.ubuntu.com/usn/usn-256-1
http://www.vupen.com/english/advisories/2006/0479
XForce ISS Database: hcidump-bluetooth-dos(24533)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24533
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.