Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.66717
Kategorie:Mandrake Local Security Checks
Titel:Mandriva Security Advisory MDVSA-2010:015 (roundcubemail)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to roundcubemail
announced via advisory MDVSA-2010:015.

Multiple vulnerabilities has been found and corrected in transmission:

A number of dependency probles were discovered and has been corrected
with this release (#56006).

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail
0.2.2 and earlier allows remote attackers to hijack the authentication
of unspecified users for requests that modify user information via
unspecified vectors, a different vulnerability than CVE-2009-4077
(CVE-2009-4076).

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail
0.2.2 and earlier allows remote attackers to hijack the authentication
of unspecified users for requests that send arbitrary emails via
unspecified vectors, a different vulnerability than CVE-2009-4076
(CVE-2009-4077).

The updated packages have been patched to correct these
issues. Additionally roundcubemail has been upgraded to 0.2.2 that
also fixes a number of upstream bugs.

Affected: Enterprise Server 5.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2010:015

Risk factor : High

CVSS Score:
6.8

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-4077
http://jvn.jp/en/jp/JVN75694913/index.html
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000072.html
http://trac.roundcube.net/wiki/Changelog
http://www.osvdb.org/59661
http://secunia.com/advisories/37235
Common Vulnerability Exposure (CVE) ID: CVE-2009-4076
http://jvn.jp/en/jp/JVN72974205/index.html
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000071.html
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.