Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.51657
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2005:108
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory RHSA-2005:108.

Python is an interpreted, interactive, object-oriented programming language.

An object traversal bug was found in the Python SimpleXMLRPCServer. This
bug could allow a remote untrusted user to do unrestricted object traversal
and allow them to access or change function internals using the im_* and
func_* attributes. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2005-0089 to this issue.

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2005-108.html
http://www.python.org/security/PSF-2005-001/

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: BugTraq ID: 12437
Common Vulnerability Exposure (CVE) ID: CVE-2005-0089
http://www.securityfocus.com/bid/12437
Bugtraq: 20050203 Python Security Advisory PSF-2005-001 - SimpleXMLRPCServer.py (Google Search)
http://marc.info/?l=bugtraq&m=110746469728728&w=2
Debian Security Information: DSA-666 (Google Search)
http://www.debian.org/security/2005/dsa-666
http://www.mandriva.com/security/advisories?name=MDKSA-2005:035
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9811
http://www.redhat.com/support/errata/RHSA-2005-108.html
http://securitytracker.com/id?1013083
http://secunia.com/advisories/14128
http://www.trustix.org/errata/2005/0003/
XForce ISS Database: python-simplexmlrpcserver-bypass(19217)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19217
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.