Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.51575
Categoría:Conectiva Local Security Checks
Título:Conectiva Security Advisory CLA-2001:412
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory CLA-2001:412.

Sendmail is a largely used Mail Transfer Agent (MTA).
Versions between (and including) 8.10.0 and 8.11.5 and some 8.12 beta
versions have a local vulnerability that allows a local attacker to
obtain root privileges.
Cade Cairns from Security Focus discovered an input validation error
in sendmail's debugging functionality. The function that handles the
-d command line option uses a signed integer for that value and
uses it as an index to an internal vector. This function does not
check for negative values of this index, which allows a local
attacker to cause a signed integer overflow by supplying large
numbers to this parameter which can be used to write data outside
that vector.
Exploits for this vulnerability have already been published.


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://www.securityspace.com/smysecure/catid.html?in=CLA-2001:412
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002001

Risk factor : High

CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.