Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.66706
Categoría:Mandrake Local Security Checks
Título:Mandriva Security Advisory MDVSA-2010:004 (bash)
Resumen:NOSUMMARY
Descripción:Description:
The remote host is missing an update to bash
announced via advisory MDVSA-2010:004.

A vulnerability have been discovered in Mandriva bash package, which
could allow a malicious user to hide files from the ls command,
or garble its output by crafting files or directories which contain
special characters or escape sequences (CVE-2010-0002). This update
fixes the issue by disabling the display of control characters
by default.

Additionally, this update fixes the unsafe file creation in bash-doc
sample scripts (CVE-2008-5374).

Packages for 2008.0 are provided for Corporate Desktop 2008.0
customers.

Affected: 2008.0, 2009.0, 2009.1, 2010.0, Corporate 4.0,
Enterprise Server 5.0, Multi Network Firewall 2.0


Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2010:004

Risk factor : High

CVSS Score:
6.9

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2010-0002
http://www.mandriva.com/security/advisories?name=MDVSA-2010:004
Common Vulnerability Exposure (CVE) ID: CVE-2008-5374
BugTraq ID: 32733
http://www.securityfocus.com/bid/32733
http://security.gentoo.org/glsa/glsa-201210-05.xml
http://uvw.ru/report.sid.txt
http://lists.debian.org/debian-devel/2008/08/msg00347.html
http://www.redhat.com/support/errata/RHSA-2011-0261.html
http://www.redhat.com/support/errata/RHSA-2011-1073.html
http://secunia.com/advisories/43365
http://secunia.com/advisories/51086
http://www.vupen.com/english/advisories/2011/0414
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.