Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.69244
Kategorie:Mandrake Local Security Checks
Titel:Mandriva Security Advisory MDVSA-2011:047 (proftpd)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to proftpd
announced via advisory MDVSA-2011:047.

A vulnerability was discovered and corrected in proftpd:

Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d
and earlier allows remote attackers to cause a denial of service
(memory consumption leading to OOM kill) via a malformed SSH message
(CVE-2011-1137).

Additionally for Mandriva Linux 2010.0 proftpd was upgraded to the
same version as in Mandriva Linux 2010.2.

The updated packages have been patched to correct this issue.

Affected: 2010.0, 2010.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2011:047

Risk factor : Medium

CVSS Score:
5.0

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-1137
BugTraq ID: 46183
http://www.securityfocus.com/bid/46183
Debian Security Information: DSA-2185 (Google Search)
http://www.debian.org/security/2011/dsa-2185
http://www.exploit-db.com/exploits/16129/
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058356.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058344.html
http://secunia.com/advisories/43234
http://secunia.com/advisories/43635
http://secunia.com/advisories/43978
http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.485806
http://www.vupen.com/english/advisories/2011/0617
http://www.vupen.com/english/advisories/2011/0857
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.