Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.51901
Categoría:Conectiva Local Security Checks
Título:Conectiva Security Advisory CLA-2005:940
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory CLA-2005:940.

cURL[1] is a client to get/put files from/to servers, using any of
the supported protocols.

This announcement fixes a remote buffer overflow vulnerability[2] in
cURL that could allow a malicious servers to execute arbitrary code
via base64 encoded replies that exceed the intended buffer lengths
when decoded, which is not properly handled by the Curl_input_ntlm
function in http_ntlm.c during NTLM authentication or the
Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos
authentication.


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://curl.haxx.se/
http://www.securityspace.com/smysecure/catid.html?in=CLA-2005:940
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=000940

Risk factor : High

CVSS Score:
5.1

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2005-0490
BugTraq ID: 12615
http://www.securityfocus.com/bid/12615
BugTraq ID: 12616
http://www.securityfocus.com/bid/12616
Conectiva Linux advisory: CLA-2005:940
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000940
http://marc.info/?l=full-disclosure&m=110959085507755&w=2
http://www.gentoo.org/security/en/glsa/glsa-200503-20.xml
http://www.idefense.com/application/poi/display?id=203&type=vulnerabilities
http://www.idefense.com/application/poi/display?id=202&type=vulnerabilities
http://www.mandriva.com/security/advisories?name=MDKSA-2005:048
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10273
http://www.redhat.com/support/errata/RHSA-2005-340.html
SuSE Security Announcement: SUSE-SA:2005:011 (Google Search)
http://www.novell.com/linux/security/advisories/2005_11_curl.html
XForce ISS Database: curl-kerberos-bo(19423)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19423
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.