Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2014.0528
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2014-0528)
Zusammenfassung:The remote host is missing an update for the 'cpio' package(s) announced via the MGASA-2014-0528 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'cpio' package(s) announced via the MGASA-2014-0528 advisory.

Vulnerability Insight:
Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11
allows remote attackers to cause a denial of service via a large block value
in a cpio archive (CVE-2014-9112).

Additionally, a null pointer dereference in the copyin_link function which
could cause a denial of service has also been fixed.

Affected Software/OS:
'cpio' package(s) on Mageia 4.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-9112
BugTraq ID: 71248
http://www.securityfocus.com/bid/71248
Debian Security Information: DSA-3111 (Google Search)
http://www.debian.org/security/2014/dsa-3111
http://seclists.org/fulldisclosure/2014/Nov/74
https://savannah.gnu.org/bugs/?43709
http://www.openwall.com/lists/oss-security/2014/11/23/2
http://www.openwall.com/lists/oss-security/2014/11/25/2
http://www.openwall.com/lists/oss-security/2014/11/26/20
http://secunia.com/advisories/60167
http://secunia.com/advisories/62145
http://www.ubuntu.com/usn/USN-2456-1
XForce ISS Database: linux-kernel-lesspipe-code-exec(98918)
https://exchange.xforce.ibmcloud.com/vulnerabilities/98918
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.