Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.702791
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 2791-1 (tryton-client - missing input sanitization)
Zusammenfassung:Cedric Krier discovered that the Tryton client does not sanitize the;file extension supplied by the server when processing reports. As a;result, a malicious server could send a report with a crafted file;extension that causes the client to write any local file to which the;user running the client has write access.
Beschreibung:Summary:
Cedric Krier discovered that the Tryton client does not sanitize the
file extension supplied by the server when processing reports. As a
result, a malicious server could send a report with a crafted file
extension that causes the client to write any local file to which the
user running the client has write access.

Affected Software/OS:
tryton-client on Debian Linux

Solution:
For the oldstable distribution (squeeze), this problem has been fixed in
version 1.6.1-1+deb6u1.

For the stable distribution (wheezy), this problem has been fixed in
version 2.2.3-1+deb7u1.

We recommend that you upgrade your tryton-client packages.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:C/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-4510
Debian Security Information: DSA-2791 (Google Search)
http://www.debian.org/security/2013/dsa-2791
http://www.openwall.com/lists/oss-security/2013/11/04/21
CopyrightCopyright (C) 2013 Greenbone Networks GmbH http://greenbone.net

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.