Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.52197
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: python, python23, python22, python-devel
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following packages are affected:

python
python23
python22
python-devel

CVE-2005-0089
The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5,
and 2.4, when used by XML-RPC servers that use the register_instance
method to register an object without a _dispatch method, allows remote
attackers to read or modify globals of the associated module, and
possibly execute arbitrary code, via dotted attributes.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2005-0089
BugTraq ID: 12437
http://www.securityfocus.com/bid/12437
Bugtraq: 20050203 Python Security Advisory PSF-2005-001 - SimpleXMLRPCServer.py (Google Search)
http://marc.info/?l=bugtraq&m=110746469728728&w=2
Debian Security Information: DSA-666 (Google Search)
http://www.debian.org/security/2005/dsa-666
http://www.mandriva.com/security/advisories?name=MDKSA-2005:035
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9811
http://www.redhat.com/support/errata/RHSA-2005-108.html
http://securitytracker.com/id?1013083
http://secunia.com/advisories/14128
http://www.trustix.org/errata/2005/0003/
XForce ISS Database: python-simplexmlrpcserver-bypass(19217)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19217
CopyrightCopyright (C) 2008 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.