Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.69244
Categoría:Mandrake Local Security Checks
Título:Mandriva Security Advisory MDVSA-2011:047 (proftpd)
Resumen:NOSUMMARY
Descripción:Description:
The remote host is missing an update to proftpd
announced via advisory MDVSA-2011:047.

A vulnerability was discovered and corrected in proftpd:

Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d
and earlier allows remote attackers to cause a denial of service
(memory consumption leading to OOM kill) via a malformed SSH message
(CVE-2011-1137).

Additionally for Mandriva Linux 2010.0 proftpd was upgraded to the
same version as in Mandriva Linux 2010.2.

The updated packages have been patched to correct this issue.

Affected: 2010.0, 2010.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2011:047

Risk factor : Medium

CVSS Score:
5.0

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-1137
BugTraq ID: 46183
http://www.securityfocus.com/bid/46183
Debian Security Information: DSA-2185 (Google Search)
http://www.debian.org/security/2011/dsa-2185
http://www.exploit-db.com/exploits/16129/
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058356.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058344.html
http://secunia.com/advisories/43234
http://secunia.com/advisories/43635
http://secunia.com/advisories/43978
http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.485806
http://www.vupen.com/english/advisories/2011/0617
http://www.vupen.com/english/advisories/2011/0857
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.