Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.70767
Categoría:Gentoo Local Security Checks
Título:Gentoo Security Advisory GLSA 201110-04 (Dovecot)
Resumen:The remote host is missing updates announced in;advisory GLSA 201110-04.
Descripción:Summary:
The remote host is missing updates announced in
advisory GLSA 201110-04.

Vulnerability Insight:
Multiple vulnerabilities were found in Dovecot, the worst of which
allowing for remote execution of arbitrary code.

Solution:
All Dovecot 1 users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose '>=net-mail/dovecot-1.2.17'


All Dovecot 2 users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose '>=net-mail/dovecot-2.0.13'


NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since May 28, 2011. It is likely that your system is
already no
longer affected by this issue.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-3235
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
BugTraq ID: 36377
http://www.securityfocus.com/bid/36377
https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00491.html
http://dovecot.org/list/dovecot-news/2009-September/000135.html
http://www.openwall.com/lists/oss-security/2009/09/14/3
http://www.osvdb.org/58103
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10515
http://secunia.com/advisories/36698
http://secunia.com/advisories/36713
http://secunia.com/advisories/36904
SuSE Security Announcement: SUSE-SR:2009:016 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
SuSE Security Announcement: SUSE-SR:2009:018 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html
http://www.ubuntu.com/usn/USN-838-1
http://www.vupen.com/english/advisories/2009/2641
http://www.vupen.com/english/advisories/2009/3184
XForce ISS Database: cmu-sieve-dovecot-unspecified-bo(53248)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53248
Common Vulnerability Exposure (CVE) ID: CVE-2009-3897
37084
http://www.securityfocus.com/bid/37084
37443
http://secunia.com/advisories/37443
60316
http://www.osvdb.org/60316
ADV-2009-3306
http://www.vupen.com/english/advisories/2009/3306
MDVSA-2009:306
http://www.mandriva.com/security/advisories?name=MDVSA-2009:306
SUSE-SR:2010:001
http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html
[dovecot-news] 20091120 v1.2.8 released
http://www.dovecot.org/list/dovecot-news/2009-November/000143.html
[oss-security] 20091120 CVE request: v1.2.8 released to fix the 0777 base_dir creation issue
http://marc.info/?l=oss-security&m=125871729029145&w=2
[oss-security] 20091121 CVE Request - Dovecot - 1.2.8
http://marc.info/?l=oss-security&m=125881481222441&w=2
[oss-security] 20091123 Re: CVE Request - Dovecot - 1.2.8
http://marc.info/?l=oss-security&m=125900271508796&w=2
[oss-security] 20091123 Re: CVE request: v1.2.8 released to fix the 0777 base_dir creation issue
http://marc.info/?l=oss-security&m=125900267208712&w=2
dovecot-basedir-privilege-escalation(54363)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54363
Common Vulnerability Exposure (CVE) ID: CVE-2010-0745
ADV-2010-1107
http://www.vupen.com/english/advisories/2010/1107
ADV-2010-1226
http://www.vupen.com/english/advisories/2010/1226
MDVSA-2010:104
http://www.mandriva.com/security/advisories?name=MDVSA-2010:104
SUSE-SR:2010:011
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html
[dovecot-news] 20100308 v1.2.11 released
http://dovecot.org/list/dovecot-news/2010-March/000152.html
[dovecot] 20100227 Possible CPU Denial-Of-Service attack to dovecot IMAP.
http://dovecot.org/pipermail/dovecot/2010-February/047190.html
[oss-security] 20100310 CVE Request -- Dovecot v1.2.11 -- DoS (excessive CPU use) by processing email with huge header
http://www.openwall.com/lists/oss-security/2010/03/10/6
[oss-security] 20100401 Re: CVE Request -- Dovecot v1.2.11 -- DoS (excessive CPU use) by processing email with huge header
http://marc.info/?l=oss-security&m=127013715227551&w=2
http://security-tracker.debian.org/tracker/CVE-2010-0745
https://bugzilla.redhat.com/show_bug.cgi?id=572268
Common Vulnerability Exposure (CVE) ID: CVE-2010-3304
41964
http://www.securityfocus.com/bid/41964
43220
http://secunia.com/advisories/43220
ADV-2010-2840
http://www.vupen.com/english/advisories/2010/2840
ADV-2011-0301
http://www.vupen.com/english/advisories/2011/0301
MDVSA-2010:217
http://www.mandriva.com/security/advisories?name=MDVSA-2010:217
SUSE-SR:2010:017
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html
USN-1059-1
http://www.ubuntu.com/usn/USN-1059-1
[dovecot-news] 20100724 v1.2.13 released
http://www.dovecot.org/list/dovecot-news/2010-July/000163.html
[oss-security] 20100916 CVE-identifier request for Dovecot ACL security bug
http://www.openwall.com/lists/oss-security/2010/09/16/14
[oss-security] 20100916 Re: CVE-identifier request for Dovecot ACL security bug
http://www.openwall.com/lists/oss-security/2010/09/16/17
Common Vulnerability Exposure (CVE) ID: CVE-2010-3706
ADV-2010-2572
http://www.vupen.com/english/advisories/2010/2572
SUSE-SR:2010:020
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html
[dovecot] 20101002 ACL handling bugs in v1.2.8+ and v2.0
http://www.dovecot.org/list/dovecot/2010-October/053452.html
[dovecot] 20101002 v1.2.15 released
http://www.dovecot.org/list/dovecot/2010-October/053450.html
[dovecot] 20101002 v2.0.5 released
http://www.dovecot.org/list/dovecot/2010-October/053451.html
[oss-security] 20101004 CVE Request: more dovecot ACL issues
http://marc.info/?l=oss-security&m=128620520732377&w=2
[oss-security] 20101004 Re: CVE Request: more dovecot ACL issues
http://marc.info/?l=oss-security&m=128622064325688&w=2
Common Vulnerability Exposure (CVE) ID: CVE-2010-3707
RHSA-2011:0600
http://www.redhat.com/support/errata/RHSA-2011-0600.html
Common Vulnerability Exposure (CVE) ID: CVE-2010-3779
Common Vulnerability Exposure (CVE) ID: CVE-2010-3780
Common Vulnerability Exposure (CVE) ID: CVE-2011-1929
44683
http://secunia.com/advisories/44683
44712
http://secunia.com/advisories/44712
44756
http://secunia.com/advisories/44756
44771
http://secunia.com/advisories/44771
44827
http://secunia.com/advisories/44827
47930
http://www.securityfocus.com/bid/47930
72495
http://osvdb.org/72495
DSA-2252
http://www.debian.org/security/2011/dsa-2252
FEDORA-2011-7258
http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060815.html
FEDORA-2011-7268
http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060825.html
FEDORA-2011-7612
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061384.html
MDVSA-2011:101
http://www.mandriva.com/security/advisories?name=MDVSA-2011:101
RHSA-2011:1187
http://www.redhat.com/support/errata/RHSA-2011-1187.html
USN-1143-1
http://www.ubuntu.com/usn/USN-1143-1
[dovecot] 20110511 v1.2.17 released
http://dovecot.org/pipermail/dovecot/2011-May/059086.html
[dovecot] 20110511 v2.0.13 released
http://dovecot.org/pipermail/dovecot/2011-May/059085.html
[oss-security] 20110518 Dovecot releases
http://openwall.com/lists/oss-security/2011/05/18/4
[oss-security] 20110519 Re: Dovecot releases
http://openwall.com/lists/oss-security/2011/05/19/3
http://openwall.com/lists/oss-security/2011/05/19/6
dovecot-header-name-dos(67589)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67589
http://hg.dovecot.org/dovecot-1.1/rev/3698dfe0f21c
http://www.dovecot.org/doc/NEWS-1.2
http://www.dovecot.org/doc/NEWS-2.0
https://bugzilla.redhat.com/show_bug.cgi?id=706286
openSUSE-SU-2011:0540
https://hermes.opensuse.org/messages/8581790
Common Vulnerability Exposure (CVE) ID: CVE-2011-2166
BugTraq ID: 48003
http://www.securityfocus.com/bid/48003
RedHat Security Advisories: RHSA-2013:0520
http://rhn.redhat.com/errata/RHSA-2013-0520.html
http://secunia.com/advisories/52311
XForce ISS Database: dovecot-scriptlogin-sec-bypass(67675)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67675
Common Vulnerability Exposure (CVE) ID: CVE-2011-2167
XForce ISS Database: dovecot-scriptlogin-dir-traversal(67674)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67674
CopyrightCopyright (C) 2012 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.