Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2014.0547
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2014-0547)
Resumen:The remote host is missing an update for the 'resteasy' package(s) announced via the MGASA-2014-0547 advisory.
Descripción:Summary:
The remote host is missing an update for the 'resteasy' package(s) announced via the MGASA-2014-0547 advisory.

Vulnerability Insight:
Updated resteasy packages fixes security vulnerability:

It was found that the fix for CVE-2012-0818 was incomplete: external
parameter entities were not disabled when the
resteasy.document.expand.entity.references parameter was set to false.
A remote attacker able to send XML requests to a RESTEasy endpoint could
use this flaw to read files accessible to the user running the application
server, and potentially perform other more advanced XXE attacks
(CVE-2014-3490).

Affected Software/OS:
'resteasy' package(s) on Mageia 4.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2014-3490
BugTraq ID: 69058
http://www.securityfocus.com/bid/69058
https://github.com/ronsigal/Resteasy/commit/9b7d0f574cafdcf3bea5428f3145ab4908fc6d83
RedHat Security Advisories: RHSA-2014:1011
http://rhn.redhat.com/errata/RHSA-2014-1011.html
RedHat Security Advisories: RHSA-2014:1039
http://rhn.redhat.com/errata/RHSA-2014-1039.html
RedHat Security Advisories: RHSA-2014:1040
http://rhn.redhat.com/errata/RHSA-2014-1040.html
RedHat Security Advisories: RHSA-2014:1298
http://rhn.redhat.com/errata/RHSA-2014-1298.html
RedHat Security Advisories: RHSA-2015:0125
http://rhn.redhat.com/errata/RHSA-2015-0125.html
RedHat Security Advisories: RHSA-2015:0675
http://rhn.redhat.com/errata/RHSA-2015-0675.html
RedHat Security Advisories: RHSA-2015:0720
http://rhn.redhat.com/errata/RHSA-2015-0720.html
RedHat Security Advisories: RHSA-2015:0765
http://rhn.redhat.com/errata/RHSA-2015-0765.html
http://secunia.com/advisories/60019
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.