Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.50995
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2003:061
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory RHSA-2003:061.

The netpbm package contains a library of functions that support
programs for handling various graphics file formats, including .pbm
(portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps),
.ppm (portable pixmaps), and others.

During an audit of the NetPBM library, Al Viro, Alan Cox, and Sebastian
Krahmer found a number of bugs that are potentially exploitable. These
bugs could be exploited by creating a carefully crafted image in such a way
that it executes arbitrary code when it is processed by either an
application from the netpbm-progs package or an application that uses the
vulnerable netpbm library.

One way that an attacker could exploit these vulnerabilities would be to
submit a carefully crafted image to be printed, as the LPRng print spooler
used by default in Red Hat Linux Advanced Products releases uses netpbm
utilities to parse various types of image files.

Users are advised to upgrade to the updated packages, which contain patches
that correct these vulnerabilities.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2003-061.html

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: BugTraq ID: 6979
Common Vulnerability Exposure (CVE) ID: CVE-2003-0146
http://www.securityfocus.com/bid/6979
Bugtraq: 20030228 NetPBM, multiple vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=104644687816522&w=2
CERT/CC vulnerability note: VU#630433
http://www.kb.cert.org/vuls/id/630433
Conectiva Linux advisory: CLSA-2003:656
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000656
Debian Security Information: DSA-263 (Google Search)
http://www.debian.org/security/2003/dsa-263
http://www.redhat.com/support/errata/RHSA-2003-060.html
XForce ISS Database: netpbm-multiple-bo(11463)
https://exchange.xforce.ibmcloud.com/vulnerabilities/11463
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.