| |||||||||||||
| ID de Prueba: | 1.3.6.1.4.1.25623.1.0.66976 |
| Categoría: | Mandrake Local Security Checks |
| Título: | Mandriva Security Advisory MDVSA-2010:054 (pam_krb5) |
| Resumen: | Mandriva Security Advisory MDVSA-2010:054 (pam_krb5) |
| Descripción: | The remote host is missing an update to pam_krb5 announced via advisory MDVSA-2010:054. Pam_krb5 2.2.14 through 2.3.4 generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames (CVE-2009-1384). This update provides the version 2.3.5 of pam_krb5, which is not vulnerable to this issue. Affected: 2009.0, 2009.1, Enterprise Server 5.0 Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2010:054 Risk factor : Medium |
| Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-1384 Bugtraq: 20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX (Google Search) http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded http://www.openwall.com/lists/oss-security/2009/05/27/1 http://www.mandriva.com/security/advisories?name=MDVSA-2010:054 BugTraq ID: 35112 http://www.securityfocus.com/bid/35112 http://osvdb.org/54791 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7081 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9652 http://secunia.com/advisories/35230 http://secunia.com/advisories/43314 http://www.vupen.com/english/advisories/2009/1448 |
| Copyright | Copyright (c) 2010 E-Soft Inc. http://www.securityspace.com |
| Esta es sólo una de 32582 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |
|