| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.902333 |
| Kategorie: | Buffer overflow |
| Titel: | Tor Unspecified Heap Based Buffer Overflow Vulnerability (Windows) |
| Zusammenfassung: | Check for the version of Tor |
| Beschreibung: | Overview: This host is installed with Tor and is prone to heap based buffer overflow vulnerability. Vulnerability Insight: The issue is caused by an unknown heap overflow error when processing user-supplied data, which can be exploited to cause a heap-based buffer overflow. Impact: Successful exploitation will allow remote attackers to execute arbitrary code in the context of the user running the application. Failed exploit attempts will likely result in denial-of-service conditions. Impact level: Application Affected Software/OS: Tor version prior to 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha on Windows. Fix: Upgrade to version 0.2.1.28 or 0.2.2.20-alpha or later http://www.torproject.org/download/download.html.en References: http://secunia.com/advisories/42536 http://www.vupen.com/english/advisories/2010/3290 |
| Querverweis: |
BugTraq ID: 45500 Common Vulnerability Exposure (CVE) ID: CVE-2010-1676 http://archives.seul.org/or/announce/Dec-2010/msg00000.html Debian Security Information: DSA-2136 (Google Search) http://www.debian.org/security/2010/dsa-2136 http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052690.html http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052657.html http://security.gentoo.org/glsa/glsa-201101-02.xml http://www.securityfocus.com/bid/45500 http://securitytracker.com/id?1024910 http://secunia.com/advisories/42536 http://secunia.com/advisories/42667 http://secunia.com/advisories/42783 http://secunia.com/advisories/42916 http://www.vupen.com/english/advisories/2010/3290 http://www.vupen.com/english/advisories/2011/0114 |
| Copyright | Copyright (C) 2011 SecPod |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|