Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.51516
Categoría:Conectiva Local Security Checks
Título:Conectiva Security Advisory CLA-2002:487
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory CLA-2002:487.

imap[4] is a package that contains POP2, POP3 and IMAP servers
developed at the University of Washington (UW).

Marcell Fodor published[1] a remote buffer overflow
vulnerability[2][3] in the IMAP server. This vulnerability can be
exploited by a remote attacker after he or she has been successfully
authenticated by the server. Arbitrary code could then be executed,
but with the privileges of the authenticated user.

This vulnerability only affects the IMAP server available in this
package.

The updated packages have been fixed with the patch made available by
the author[5].


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://online.securityfocus.com/archive/1/272030/2002-05-07/2002-05-13/2
http://www.securityspace.com/smysecure/catid.html?in=CLA-2002:487
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002002

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: BugTraq ID: 4713
Common Vulnerability Exposure (CVE) ID: CVE-2002-0379
http://www.securityfocus.com/bid/4713
Bugtraq: 20020510 wu-imap buffer overflow condition (Google Search)
http://marc.info/?l=bugtraq&m=102107222100529&w=2
Caldera Security Advisory: CSSA-2002-021.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-021.0.txt
CERT/CC vulnerability note: VU#961489
http://www.kb.cert.org/vuls/id/961489
Conectiva Linux advisory: CLA-2002:487
http://distro.conectiva.com/atualizacoes/?id=a&anuncio=000487
En Garde Linux Advisory: ESA-20020607-013
http://www.linuxsecurity.com/advisories/other_advisory-2120.html
HPdes Security Advisory: HPSBTL0205-043
http://online.securityfocus.com/advisories/4167
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-034.php
http://www.redhat.com/support/errata/RHSA-2002-092.html
XForce ISS Database: wuimapd-authenticated-user-bo(10803)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10803
http://www.iss.net/security_center/static/9055.php
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.