Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.831429
Kategorie:Mandrake Local Security Checks
Titel:Mandriva Update for curl MDVSA-2011:116 (curl)
Zusammenfassung:The remote host is missing an update for the 'curl'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'curl'
package(s) announced via the referenced advisory.

Vulnerability Insight:
A vulnerability was discovered and corrected in curl:

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6
through 7.21.6, as used in curl and other products, always performs
credential delegation during GSSAPI authentication, which allows remote
servers to impersonate clients via GSSAPI requests (CVE-2011-2192).

Packages for 2009.0 are provided as of the Extended Maintenance
Program. The updated packages have been patched to correct this issue.

Affected Software/OS:
curl on Mandriva Linux 2009.0,
Mandriva Linux 2009.0/X86_64,
Mandriva Linux 2010.1,
Mandriva Linux 2010.1/X86_64,
Mandriva Enterprise Server 5,
Mandriva Enterprise Server 5/X86_64

Solution:
Please Install the Updated Packages.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-2192
1025713
http://www.securitytracker.com/id?1025713
45047
http://secunia.com/advisories/45047
45067
http://secunia.com/advisories/45067
45088
http://secunia.com/advisories/45088
45144
http://secunia.com/advisories/45144
45181
http://secunia.com/advisories/45181
48256
http://secunia.com/advisories/48256
APPLE-SA-2012-02-01-1
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
DSA-2271
http://www.debian.org/security/2011/dsa-2271
FEDORA-2011-8586
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061992.html
FEDORA-2011-8640
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062287.html
GLSA-201203-02
http://security.gentoo.org/glsa/glsa-201203-02.xml
MDVSA-2011:116
http://www.mandriva.com/security/advisories?name=MDVSA-2011:116
RHSA-2011:0918
http://www.redhat.com/support/errata/RHSA-2011-0918.html
USN-1158-1
http://www.ubuntu.com/usn/USN-1158-1
http://curl.haxx.se/curl-gssapi-delegation.patch
http://curl.haxx.se/docs/adv_20110623.html
http://support.apple.com/kb/HT5130
https://bugzilla.redhat.com/show_bug.cgi?id=711454
CopyrightCopyright (C) 2011 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.