Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.56846
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2006:0533
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing updates announced in
advisory RHSA-2006:0533.

GNU Zebra is a free software that manages TCP/IP based routing protocol.

An information disclosure flaw was found in the way GNU Zebra interprets
RIP REQUEST packets. RIPd in GNU Zebra will respond to RIP REQUEST packets
for RIP versions that have been disabled or that have authentication
enabled, allowing a remote attacker to acquire information about the local
network. (CVE-2006-2223)

A route injection flaw was found in the way GNU Zebra interprets RIPv1
RESPONSE packets when RIPv2 authentication is enabled. It is possible for a
remote attacker to inject arbitrary route information into the RIPd routing
tables. This issue does not affect GNU Zebra configurations where only
RIPv2 is specified. (CVE-2006-2224)

A denial of service flaw was found in GNU Zebra's telnet interface. If an
attacker is able to connect to the GNU Zebra telnet interface, it is
possible to cause GNU Zebra to consume vast quantities of CPU resources by
issuing a malformed 'sh' command. (CVE-2006-2276)

Users of GNU Zebra should upgrade to these updated packages, which contain
backported patches that correct these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2006-0533.html
http://www.redhat.com/security/updates/classification/#moderate

Risk factor : Medium

CVSS Score:
5.0

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2006-2223
BugTraq ID: 17808
http://www.securityfocus.com/bid/17808
Bugtraq: 20060503 Quagga RIPD unauthenticated route table broadcast (Google Search)
http://www.securityfocus.com/archive/1/432822/100/0/threaded
Bugtraq: 20060503 Re: Quagga RIPD unauthenticated route injection (Google Search)
http://www.securityfocus.com/archive/1/432823/100/0/threaded
Debian Security Information: DSA-1059 (Google Search)
http://www.debian.org/security/2006/dsa-1059
http://www.gentoo.org/security/en/glsa/glsa-200605-15.xml
http://www.osvdb.org/25224
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9985
http://www.redhat.com/support/errata/RHSA-2006-0525.html
http://www.redhat.com/support/errata/RHSA-2006-0533.html
http://securitytracker.com/id?1016204
http://secunia.com/advisories/19910
http://secunia.com/advisories/20137
http://secunia.com/advisories/20138
http://secunia.com/advisories/20221
http://secunia.com/advisories/20420
http://secunia.com/advisories/20421
http://secunia.com/advisories/20782
http://secunia.com/advisories/21159
SGI Security Advisory: 20060602-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc
SuSE Security Announcement: SUSE-SR:2006:017 (Google Search)
http://www.novell.com/linux/security/advisories/2006_17_sr.html
https://usn.ubuntu.com/284-1/
XForce ISS Database: quagga-ripv1-information-disclosure(26243)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26243
Common Vulnerability Exposure (CVE) ID: CVE-2006-2224
Bugtraq: 20060503 Quagga RIPD unauthenticated route injection (Google Search)
http://www.securityfocus.com/archive/1/432856/100/0/threaded
http://www.osvdb.org/25225
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10775
XForce ISS Database: quagga-ripd-ripv1-response-security-bypass(26251)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26251
Common Vulnerability Exposure (CVE) ID: CVE-2006-2276
BugTraq ID: 17979
http://www.securityfocus.com/bid/17979
http://lists.quagga.net/pipermail/quagga-dev/2006-March/004052.html
http://www.osvdb.org/25245
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10651
http://secunia.com/advisories/20116
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.