Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.831513
Kategorie:Mandrake Local Security Checks
Titel:Mandriva Update for libarchive MDVSA-2011:190 (libarchive)
Zusammenfassung:The remote host is missing an update for the 'libarchive'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'libarchive'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Two heap-based buffer overflow flaws were discovered in libarchive. If
a user were tricked into expanding a specially-crafted ISO 9660
CD-ROM image or tar archive with an application using libarchive,
it could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application
(CVE-2011-1777, CVE-2011-1778).

The updated packages have been patched to correct these issues.

Affected Software/OS:
libarchive on Mandriva Linux 2010.1,
Mandriva Linux 2010.1/X86_64

Solution:
Please Install the Updated Packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-1777
48034
http://secunia.com/advisories/48034
APPLE-SA-2012-05-09-1
http://lists.apple.com/archives/security-announce/2012/May/msg00001.html
DSA-2413
http://www.debian.org/security/2012/dsa-2413
RHSA-2011:1507
https://rhn.redhat.com/errata/RHSA-2011-1507.html
http://code.google.com/p/libarchive/source/detail?r=3158
http://support.apple.com/kb/HT5281
https://bugzilla.redhat.com/show_bug.cgi?id=705849
Common Vulnerability Exposure (CVE) ID: CVE-2011-1778
http://code.google.com/p/libarchive/source/detail?r=3160
CopyrightCopyright (C) 2011 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.