Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.63357
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: amaya
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: amaya

CVE-2008-5282
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1
allow remote attackers to execute arbitrary code via (1) a link with a
long HREF attribute, and (2) a DIV tag with a long id attribute.

CVE-2009-0323
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0
and 11.0 allow remote attackers to execute arbitrary code via (1) a
long type parameter in an input tag, which is not properly handled by
the EndOfXmlAttributeValue function, (2) an 'HTML GI' in a start tag,
which is not properly handled by the ProcessStartGI function, and
unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to
the msgBuffer variable. NOTE: these are different vectors than
CVE-2008-6005.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2008-5282
BugTraq ID: 32442
http://www.securityfocus.com/bid/32442
Bugtraq: 20081124 Amaya (URL Bar) Remote Stack Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/498578/100/0/threaded
Bugtraq: 20081124 Amaya (id) Remote Stack Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/498583/100/0/threaded
http://www.bmgsec.com.au/advisory/40/
http://www.bmgsec.com.au/advisory/41/
http://osvdb.org/50282
http://osvdb.org/50283
http://secunia.com/advisories/32848
http://securityreason.com/securityalert/4657
http://www.vupen.com/english/advisories/2008/3255
Common Vulnerability Exposure (CVE) ID: CVE-2009-0323
Bugtraq: 20090128 CORE-2008-1211: Amaya web editor XML and HTML parser vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/500492/100/0/threaded
https://www.exploit-db.com/exploits/7902
http://www.coresecurity.com/content/amaya-buffer-overflows
XForce ISS Database: amaya-html-tags-bo(48325)
https://exchange.xforce.ibmcloud.com/vulnerabilities/48325
CopyrightCopyright (C) 2009 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.