Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.870864
Categoría:Red Hat Local Security Checks
Título:RedHat Update for gegl RHSA-2012:1455-01
Resumen:The remote host is missing an update for the 'gegl'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'gegl'
package(s) announced via the referenced advisory.

Vulnerability Insight:
GEGL (Generic Graphics Library) is a graph-based image processing
framework.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the gegl utility processed .ppm (Portable Pixel Map) image
files. An attacker could create a specially-crafted .ppm file that, when
opened in gegl, would cause gegl to crash or, potentially, execute
arbitrary code. (CVE-2012-4433)

This issue was discovered by Murray McAllister of the Red Hat Security
Response Team.

Users of gegl should upgrade to these updated packages, which contain a
backported patch to correct this issue.

Affected Software/OS:
gegl on Red Hat Enterprise Linux Desktop (v. 6),
Red Hat Enterprise Linux Server (v. 6),
Red Hat Enterprise Linux Workstation (v. 6)

Solution:
Please Install the Updated Packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2012-4433
1027754
http://www.securitytracker.com/id?1027754
51114
http://secunia.com/advisories/51114
51274
http://secunia.com/advisories/51274
56404
http://www.securityfocus.com/bid/56404
MDVSA-2013:081
http://www.mandriva.com/security/advisories?name=MDVSA-2013:081
RHSA-2012:1455
http://rhn.redhat.com/errata/RHSA-2012-1455.html
[oss-security] 20121106 gegl: Integer overflow, leading to heap-based buffer overflow by parsing PPM image headers
http://www.openwall.com/lists/oss-security/2012/11/06/1
gegl-ppm-bo(79822)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79822
http://git.gnome.org/browse/gegl/commit/?id=1e92e5235ded0415d555aa86066b8e4041ee5a53
http://git.gnome.org/browse/gegl/commit/?id=4757cdf73d3675478d645a3ec8250ba02168a230
https://bugzilla.redhat.com/show_bug.cgi?id=856300
openSUSE-SU-2013:0159
http://lists.opensuse.org/opensuse-updates/2013-01/msg00054.html
CopyrightCopyright (C) 2012 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.