Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.68341
Kategorie:Mandrake Local Security Checks
Titel:Mandriva Security Advisory MDVSA-2010:208 (pidgin)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to pidgin
announced via advisory MDVSA-2010:208.

A security vulnerability has been identified and fixed in pidgin:

It has been discovered that eight denial of service conditions exist
in libpurple all due to insufficient validation of the return value
from purple_base64_decode(). Invalid or malformed data received in
place of a valid base64-encoded value in portions of the Yahoo!, MSN,
MySpaceIM, and XMPP protocol plugins and the NTLM authentication
support trigger a crash. These vulnerabilities can be leveraged by
a remote user for denial of service (CVE-2010-3711).

Packages for 2009.0 are provided as of the Extended Maintenance
Program. Please visit this link to learn more:
http://store.mandriva.com/product_info.php?cPath=149&products_id=490

This update provides pidgin 2.7.4, which is not vulnerable to this
issue.

Affected: 2009.0, 2010.0, 2010.1, Enterprise Server 5.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2010:208
http://pidgin.im/news/security/

Risk factor : Medium

CVSS Score:
4.0

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-3711
1024623
http://securitytracker.com/id?1024623
41893
http://secunia.com/advisories/41893
41899
http://secunia.com/advisories/41899
42075
http://secunia.com/advisories/42075
42294
http://secunia.com/advisories/42294
44283
http://www.securityfocus.com/bid/44283
68773
http://www.osvdb.org/68773
ADV-2010-2753
http://www.vupen.com/english/advisories/2010/2753
ADV-2010-2754
http://www.vupen.com/english/advisories/2010/2754
ADV-2010-2755
http://www.vupen.com/english/advisories/2010/2755
ADV-2010-2847
http://www.vupen.com/english/advisories/2010/2847
ADV-2010-2851
http://www.vupen.com/english/advisories/2010/2851
ADV-2010-2870
http://www.vupen.com/english/advisories/2010/2870
FEDORA-2010-16629
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050227.html
FEDORA-2010-16876
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050133.html
FEDORA-2010-17130
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050695.html
MDVSA-2010:208
http://www.mandriva.com/security/advisories?name=MDVSA-2010:208
RHSA-2010:0788
http://www.redhat.com/support/errata/RHSA-2010-0788.html
RHSA-2010:0890
http://www.redhat.com/support/errata/RHSA-2010-0890.html
SSA:2010-305-02
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.462352
USN-1014-1
http://www.ubuntu.com/usn/USN-1014-1
http://developer.pidgin.im/viewmtn/revision/info/b01c6a1f7fe4d86b83f5f10917b3cb713989cfcc
http://pidgin.im/news/security/?id=48
https://bugzilla.redhat.com/show_bug.cgi?id=641921
oval:org.mitre.oval:def:18506
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18506
pidgin-purplebase64decode-dos(62708)
https://exchange.xforce.ibmcloud.com/vulnerabilities/62708
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.