Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2013.0384
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2013-0384)
Zusammenfassung:The remote host is missing an update for the 'asterisk' package(s) announced via the MGASA-2013-0384 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'asterisk' package(s) announced via the MGASA-2013-0384 advisory.

Vulnerability Insight:
Updated asterisk packages fix security vulnerability:

Buffer overflow in the unpacksms16 function in apps/app_sms.c in
Asterisk Open Source 1.8.x before 1.8.24.1, 10.x before 10.12.4, and
11.x before 11.6.1, Asterisk with Digiumphones 10.x-digiumphones before
10.12.4-digiumphones, and Certified Asterisk 1.8.x before 1.8.15-cert4
and 11.x before 11.2-cert3 allows remote attackers to cause a denial
of service (daemon crash) via a 16-bit SMS message (CVE-2013-7100).

The updated packages has been upgraded to the 11.7.0 version which
resolves various upstream bugs and is not vulnerable to this issue.

Affected Software/OS:
'asterisk' package(s) on Mageia 3.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-7100
BugTraq ID: 64364
http://www.securityfocus.com/bid/64364
Bugtraq: 20131216 AST-2013-006: Buffer Overflow when receiving odd length 16 bit SMS message (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2013-12/0089.html
Debian Security Information: DSA-2835 (Google Search)
http://www.debian.org/security/2014/dsa-2835
http://www.mandriva.com/security/advisories?name=MDVSA-2013:300
http://osvdb.org/101100
http://www.securitytracker.com/id/1029499
http://secunia.com/advisories/56294
XForce ISS Database: asterisk-sms-message-dos(89825)
https://exchange.xforce.ibmcloud.com/vulnerabilities/89825
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.