Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.63484
Kategorie:Mandrake Local Security Checks
Titel:Mandrake Security Advisory MDVSA-2009:067 (libsndfile)
Zusammenfassung:The remote host is missing an update to libsndfile;announced via advisory MDVSA-2009:067.
Beschreibung:Summary:
The remote host is missing an update to libsndfile
announced via advisory MDVSA-2009:067.

Vulnerability Insight:
Crafted data - channels per frame value - in CAF files enables remote
attackers to execute arbitrary code or denial of service via a possible
integer overflow, leading to a possible heap overflow (CVE-2009-0186).

This update provides fix for that vulnerability.

Affected: 2008.0, 2008.1, 2009.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-0186
BugTraq ID: 33963
http://www.securityfocus.com/bid/33963
Bugtraq: 20090303 Secunia Research: Winamp CAF Processing Integer Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/501399/100/0/threaded
Bugtraq: 20090303 Secunia Research: libsndfile CAF Processing Integer Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/501413/100/0/threaded
Debian Security Information: DSA-1742 (Google Search)
http://www.debian.org/security/2009/dsa-1742
http://security.gentoo.org/glsa/glsa-200904-16.xml
http://secunia.com/secunia_research/2009-7/
http://secunia.com/secunia_research/2009-8/
http://www.securitytracker.com/id?1021784
http://secunia.com/advisories/33980
http://secunia.com/advisories/33981
http://secunia.com/advisories/34316
http://secunia.com/advisories/34526
http://secunia.com/advisories/34642
http://secunia.com/advisories/34791
SuSE Security Announcement: SUSE-SR:2009:008 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html
http://www.ubuntu.com/usn/USN-749-1
http://www.vupen.com/english/advisories/2009/0584
http://www.vupen.com/english/advisories/2009/0585
XForce ISS Database: libsndfile-caf-bo(49038)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49038
CopyrightCopyright (C) 2009 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.