Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.56704
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2006:0425
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory RHSA-2006:0425.

The libtiff package contains a library of functions for manipulating TIFF
(Tagged Image File Format) image format files.

An integer overflow flaw was discovered in libtiff. An attacker could
create a carefully crafted TIFF file in such a way that it could cause an
application linked with libtiff to crash or possibly execute arbitrary
code. (CVE-2006-2025)

A double free flaw was discovered in libtiff. An attacker could create a
carefully crafted TIFF file in such a way that it could cause an
application linked with libtiff to crash or possibly execute arbitrary
code. (CVE-2006-2026)

Several denial of service flaws were discovered in libtiff. An attacker
could create a carefully crafted TIFF file in such a way that it could
cause an application linked with libtiff to crash. (CVE-2006-2024,
CVE-2006-2120)

All users are advised to upgrade to these updated packages, which contain
backported fixes for these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2006-0425.html
http://www.redhat.com/security/updates/classification/#important

Risk factor : High

CVSS Score:
6.5

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2006-2024
BugTraq ID: 17730
http://www.securityfocus.com/bid/17730
Debian Security Information: DSA-1054 (Google Search)
http://www.debian.org/security/2006/dsa-1054
http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:082
http://bugzilla.remotesensing.org/show_bug.cgi?id=1102
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9893
http://www.redhat.com/support/errata/RHSA-2006-0425.html
http://secunia.com/advisories/19838
http://secunia.com/advisories/19851
http://secunia.com/advisories/19897
http://secunia.com/advisories/19936
http://secunia.com/advisories/19949
http://secunia.com/advisories/19964
http://secunia.com/advisories/20021
http://secunia.com/advisories/20023
http://secunia.com/advisories/20210
http://secunia.com/advisories/20345
http://secunia.com/advisories/20667
SGI Security Advisory: 20060501-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103099-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201332-1
SuSE Security Announcement: SUSE-SR:2006:009 (Google Search)
http://www.novell.com/linux/security/advisories/2006_04_28.html
http://www.trustix.org/errata/2006/0024
https://usn.ubuntu.com/277-1/
http://www.vupen.com/english/advisories/2006/1563
XForce ISS Database: libtiff-tifffetchanyarray-dos(26133)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26133
Common Vulnerability Exposure (CVE) ID: CVE-2006-2025
BugTraq ID: 17732
http://www.securityfocus.com/bid/17732
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10593
XForce ISS Database: libtiff-tifffetchdata-overflow(26134)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26134
Common Vulnerability Exposure (CVE) ID: CVE-2006-2026
BugTraq ID: 17733
http://www.securityfocus.com/bid/17733
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11389
XForce ISS Database: libtiff-tifjpeg-doublefree-memory-corruption(26135)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26135
Common Vulnerability Exposure (CVE) ID: CVE-2006-2120
17809
http://www.securityfocus.com/bid/17809
19936
19949
19964
20023
2006-0024
20060501-01-U
20210
20330
http://secunia.com/advisories/20330
20667
DSA-1078
http://www.debian.org/security/2006/dsa-1078
MDKSA-2006:082
RHSA-2006:0425
USN-277-1
http://bugzilla.remotesensing.org/show_bug.cgi?id=1065
http://support.avaya.com/elmodocs2/security/ASA-2006-119.htm
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189974
oval:org.mitre.oval:def:9572
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9572
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.