Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2019.0002
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2019-0002)
Zusammenfassung:The remote host is missing an update for the 'xmlrpc' package(s) announced via the MGASA-2019-0002 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'xmlrpc' package(s) announced via the MGASA-2019-0002 advisory.

Vulnerability Insight:
XML external entity (XXE) vulnerability in the Apache XML-RPC
(aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote
attackers to conduct server-side request forgery (SSRF) attacks via a
crafted DTD (CVE-2016-5002).

A flaw was discovered in the Apache XML-RPC (ws-xmlrpc) library that
deserializes untrusted data when enabledForExtensions setting is
enabled. A remote attacker could use this vulnerability to execute
arbitrary code via a crafted serialized Java object in a
element (CVE-2016-5003).

Affected Software/OS:
'xmlrpc' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-5002
https://security.gentoo.org/glsa/202401-26
1036294
http://www.securitytracker.com/id/1036294
91736
http://www.securityfocus.com/bid/91736
RHSA-2018:3768
https://access.redhat.com/errata/RHSA-2018:3768
[oss-security] 20160712 Vulnerabilities in Apache Archiva
http://www.openwall.com/lists/oss-security/2016/07/12/5
apache-archiva-cve20165002-ssrf(115042)
https://exchange.xforce.ibmcloud.com/vulnerabilities/115042
https://0ang3el.blogspot.in/2016/07/beware-of-ws-xmlrpc-library-in-your.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-5003
91738
http://www.securityfocus.com/bid/91738
RHSA-2018:1779
https://access.redhat.com/errata/RHSA-2018:1779
RHSA-2018:1780
https://access.redhat.com/errata/RHSA-2018:1780
RHSA-2018:1784
https://access.redhat.com/errata/RHSA-2018:1784
RHSA-2018:2317
https://access.redhat.com/errata/RHSA-2018:2317
[oss-security] 20200116 [CVE-2019-17570] xmlrpc-common untrusted deserialization
http://www.openwall.com/lists/oss-security/2020/01/16/1
[oss-security] 20200124 RE: [CVE-2019-17570] xmlrpc-common untrusted deserialization
http://www.openwall.com/lists/oss-security/2020/01/24/2
apache-archiva-cve20165003-code-exec(115043)
https://exchange.xforce.ibmcloud.com/vulnerabilities/115043
https://0ang3el.blogspot.ru/2016/07/beware-of-ws-xmlrpc-library-in-your.html
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.