Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.51229
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2002:191
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory RHSA-2002:191.

Updated gaim packages are now available for Red Hat Linux Advanced Server.
These updates fix a vulnerability in the default URL handler.

Gaim is an all-in-one instant messaging client that lets you use a number of
messaging protocols such as AIM, ICQ, and Yahoo, all at once.

Versions of gaim prior to 0.59.1 contain a bug in the URL handler of
the manual browser option. A link can be carefully crafted to contain
an arbitrary shell script which will be executed if the user clicks on
the link.

Users of gaim should update to these errata packages containing gaim
0.59.1 which is not vulnerable to this issue.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2002-191.html
http://gaim.sourceforge.net/ChangeLog

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: BugTraq ID: 5574
Common Vulnerability Exposure (CVE) ID: CVE-2002-0989
http://www.securityfocus.com/bid/5574
Bugtraq: 20020827 GLSA: gaim (Google Search)
http://marc.info/?l=bugtraq&m=103046442403404&w=2
Conectiva Linux advisory: CLA-2002:521
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000521
Debian Security Information: DSA-158 (Google Search)
http://www.debian.org/security/2002/dsa-158
FreeBSD Security Advisory: FreeBSD-SN-02:06
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:06.asc
HPdes Security Advisory: HPSBTL0209-067
http://online.securityfocus.com/advisories/4471
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:054
http://www.osvdb.org/5033
http://www.redhat.com/support/errata/RHSA-2002-189.html
http://www.redhat.com/support/errata/RHSA-2002-190.html
http://www.redhat.com/support/errata/RHSA-2002-191.html
http://www.redhat.com/support/errata/RHSA-2003-156.html
http://www.iss.net/security_center/static/9978.php
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.