| |||||||||||||
| ID de Prueba: | 1.3.6.1.4.1.25623.1.0.53165 |
| Categoría: | Debian Local Security Checks |
| Título: | Debian Security Advisory DSA 468-1 (emil) |
| Resumen: | Debian Security Advisory DSA 468-1 (emil) |
| Descripción: | The remote host is missing an update to emil announced via advisory DSA 468-1. Ulf Harnhammar discovered a number of vulnerabilities in emil, a filter for converting Internet mail messages. The vulnerabilities fall into two categories: - CVE-2004-0152 - Buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) the decode_uuencode function. These bugs could allow a carefully crafted email message to cause the execution of arbitrary code supplied with the message when it is acted upon by emil. - CVE-2004-0153 - Format string bugs in statements which print various error messages. The exploit potential of these bugs has not been established, and is probably configuration-dependent. For the stable distribution (woody) these problems have been fixed in version 2.1.0-beta9-11woody1. For the unstable distribution (sid) these problems will be fixed soon. We recommend that you update your emil package. Solution: http://www.securityspace.com/smysecure/catid.html?in=DSA%20468-1 |
| Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2004-0152 Bugtraq: 20040325 Re: [SECURITY] [DSA 468-1] New emil packages fix multiple vulnerabilities (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=108024939827236&w=2 Debian Security Information: DSA-468 (Google Search) http://www.debian.org/security/2004/dsa-468 SuSE Security Announcement: SuSE-SA:2004:008 (Google Search) XForce ISS Database: emil-email-bo(15601) http://xforce.iss.net/xforce/xfdb/15601 Common Vulnerability Exposure (CVE) ID: CVE-2004-0153 XForce ISS Database: emil-format-string(15602) http://xforce.iss.net/xforce/xfdb/15602 |
| Copyright | Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com |
| Esta es sólo una de 32582 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |
|