| |||||||||||||
| ID de Prueba: | 1.3.6.1.4.1.25623.1.0.66122 |
| Categoría: | Red Hat Local Security Checks |
| Título: | RedHat Security Advisory RHSA-2009:1535 |
| Resumen: | Redhat Security Advisory RHSA-2009:1535 |
| Descripción: | The remote host is missing updates announced in advisory RHSA-2009:1535. Pidgin is an instant messaging program which can log in to multiple accounts on multiple instant messaging networks simultaneously. An invalid pointer dereference bug was found in the way the Pidgin OSCAR protocol implementation processed lists of contacts. A remote attacker could send a specially-crafted contact list to a user running Pidgin, causing Pidgin to crash. (CVE-2009-3615) A NULL pointer dereference flaw was found in the way the Pidgin IRC protocol plug-in handles IRC topics. A malicious IRC server could send a specially-crafted IRC TOPIC message, which once received by Pidgin, would lead to a denial of service (Pidgin crash). (CVE-2009-2703) A NULL pointer dereference flaw was found in the way the Pidgin MSN protocol plug-in handles improper MSNSLP invitations. A remote attacker could send a specially-crafted MSNSLP invitation request, which once accepted by a valid Pidgin user, would lead to a denial of service (Pidgin crash). (CVE-2009-3083) All Pidgin users should upgrade to this updated package, which contains backported patches to resolve these issues. Pidgin must be restarted for this update to take effect. Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date http://rhn.redhat.com/errata/RHSA-2009-1535.html http://www.redhat.com/security/updates/classification/#moderate |
| Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-2703 BugTraq ID: 36277 http://www.securityfocus.com/bid/36277 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11379 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6435 http://secunia.com/advisories/36601 Common Vulnerability Exposure (CVE) ID: CVE-2009-3083 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11852 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6322 Common Vulnerability Exposure (CVE) ID: CVE-2009-3615 http://www.mandriva.com/security/advisories?name=MDVSA-2010:085 BugTraq ID: 36719 http://www.securityfocus.com/bid/36719 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9414 http://secunia.com/advisories/37017 http://secunia.com/advisories/37072 http://www.vupen.com/english/advisories/2009/2949 http://www.vupen.com/english/advisories/2009/2951 http://www.vupen.com/english/advisories/2010/1020 XForce ISS Database: pidgin-oscar-protocol-dos(53807) http://xforce.iss.net/xforce/xfdb/53807 |
| Copyright | Copyright (c) 2009 E-Soft Inc. http://www.securityspace.com |
| Esta es sólo una de 32582 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |
|