Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.10833
Categoría:Gain root remotely
Título:dtspcd overflow
Resumen:NOSUMMARY
Descripción:Description:

The 'dtspcd' service is running. This service deals with
the CDE interface for the X11 system.

Some versions of this daemon are vulnerable to a buffer overflow
attack which may allow an attacker to gain root privileges on
this host.

*** This warning might be a false positive,
*** as no real overflow was performed

Solution : See http://www.cert.org/advisories/CA-2001-31.html
to determine if you are vulnerable or deactivate this service
(comment out the line 'dtspc' in /etc/inetd.conf and restart the inetd process)

Risk factor : High

Referencia Cruzada: BugTraq ID: 3517
Common Vulnerability Exposure (CVE) ID: CVE-2001-0803
http://www.securityfocus.com/bid/3517
Caldera Security Advisory: CSSA-2001-SCO.30
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/
http://www.cert.org/advisories/CA-2001-31.html
http://www.cert.org/advisories/CA-2002-01.html
CERT/CC vulnerability note: VU#172583
http://www.kb.cert.org/vuls/id/172583
COMPAQ Service Security Patch: SSRT541
http://ftp.support.compaq.com/patches/.new/html/SSRT-541.shtml
HPdes Security Advisory: HPSBUX0111-175
http://www.securityfocus.com/advisories/3651
ISS Security Advisory: 20011112 Multi-Vendor Buffer Overflow Vulnerability in CDE Subprocess Control Service
http://xforce.iss.net/alerts/advise101.php
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A70
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A74
SGI Security Advisory: 20011107-01-P
ftp://patches.sgi.com/support/free/security/advisories/20011107-01-P
Sun Security Bulletin: 00214
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/214
XForce ISS Database: cde-dtspcd-bo(7396)
https://exchange.xforce.ibmcloud.com/vulnerabilities/7396
CopyrightThis script is Copyright (C) 2002 Renaud Deraison

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.