Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.52535
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: lftp
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: lftp

CVE-2003-0963
Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for
lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary
code via long directory names that are processed by the ls or rels
commands.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2003-0963
Bugtraq: 20031212 [slackware-security] lftp security update (SSA:2003-346-01) (Google Search)
http://marc.info/?l=bugtraq&m=107126386226196&w=2
Bugtraq: 20031213 lftp buffer overflows (Google Search)
http://marc.info/?l=bugtraq&m=107152267121513&w=2
Bugtraq: 20031217 [OpenPKG-SA-2003.053] OpenPKG Security Advisory (lftp) (Google Search)
http://marc.info/?l=bugtraq&m=107167974714484&w=2
Bugtraq: 20031218 GLSA: lftp (200312-07) (Google Search)
http://marc.info/?l=bugtraq&m=107177409418121&w=2
Conectiva Linux advisory: CLA-2004:800
http://marc.info/?l=bugtraq&m=107340499504411&w=2
Debian Security Information: DSA-406 (Google Search)
http://www.debian.org/security/2004/dsa-406
http://www.mandriva.com/security/advisories?name=MDKSA-2003:116
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11180
http://www.redhat.com/support/errata/RHSA-2003-403.html
http://www.redhat.com/support/errata/RHSA-2003-404.html
http://secunia.com/advisories/10525
http://secunia.com/advisories/10548
SGI Security Advisory: 20040101-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040101-01-U
SGI Security Advisory: 20040202-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
SuSE Security Announcement: SuSE-SA:2003:051 (Google Search)
http://www.novell.com/linux/security/advisories/2003_051_lftp.html
CopyrightCopyright (C) 2008 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.