Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.66693
Categoría:Red Hat Local Security Checks
Título:RedHat Security Advisory RHSA-2010:0044
Resumen:NOSUMMARY
Descripción:Description:
The remote host is missing updates announced in
advisory RHSA-2010:0044.

Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

A directory traversal flaw was discovered in Pidgin's MSN protocol
implementation. A remote attacker could send a specially-crafted emoticon
image download request that would cause Pidgin to disclose an arbitrary
file readable to the user running Pidgin. (CVE-2010-0013)

These packages upgrade Pidgin to version 2.6.5. Refer to the Pidgin release
notes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which correct
this issue. Pidgin must be restarted for this update to take effect.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2010-0044.html
http://www.redhat.com/security/updates/classification/#important

Risk factor : Medium

CVSS Score:
5.0

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-0013
1022203
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022203.1-1
277450
http://sunsolve.sun.com/search/document.do?assetkey=1-66-277450-1
37953
http://secunia.com/advisories/37953
37954
http://secunia.com/advisories/37954
37961
http://secunia.com/advisories/37961
38915
http://secunia.com/advisories/38915
ADV-2009-3662
http://www.vupen.com/english/advisories/2009/3662
ADV-2009-3663
http://www.vupen.com/english/advisories/2009/3663
ADV-2010-1020
http://www.vupen.com/english/advisories/2010/1020
FEDORA-2010-0368
http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033771.html
FEDORA-2010-0429
http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033848.html
MDVSA-2010:085
http://www.mandriva.com/security/advisories?name=MDVSA-2010:085
SUSE-SR:2010:006
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html
[oss-security] 20100102 CVE request - pidgin MSN arbitrary file upload
http://www.openwall.com/lists/oss-security/2010/01/02/1
[oss-security] 20100107 Re: CVE request - pidgin MSN arbitrary file upload
http://www.openwall.com/lists/oss-security/2010/01/07/1
http://www.openwall.com/lists/oss-security/2010/01/07/2
http://d.pidgin.im/viewmtn/revision/info/3d02401cf232459fc80c0837d31e05fae7ae5467
http://d.pidgin.im/viewmtn/revision/info/4be2df4f72bd8a55cdae7f2554b73342a497c92f
http://d.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810
http://developer.pidgin.im/viewmtn/revision/diff/3d02401cf232459fc80c0837d31e05fae7ae5467/with/c64a1adc8bda2b4aeaae1f273541afbc4f71b810/libpurple/protocols/msn/slp.c
http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html
https://bugzilla.redhat.com/show_bug.cgi?id=552483
oval:org.mitre.oval:def:10333
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10333
oval:org.mitre.oval:def:17620
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17620
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.