Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2017.0475
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2017-0475)
Resumen:The remote host is missing an update for the 'freerdp' package(s) announced via the MGASA-2017-0475 advisory.
Descripción:Summary:
The remote host is missing an update for the 'freerdp' package(s) announced via the MGASA-2017-0475 advisory.

Vulnerability Insight:
An exploitable code execution vulnerability exists in the authentication
functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted
server response can cause an out-of-bounds write resulting in an
exploitable condition. An attacker can compromise the server or use a
man in the middle attack to trigger this vulnerability (CVE-2017-2834).

An exploitable code execution vulnerability exists in the RDP receive
functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted
server response can cause an out-of-bounds write resulting in an
exploitable condition. An attacker can compromise the server or use a
man in the middle to trigger this vulnerability (CVE-2017-2835).

An exploitable denial of service vulnerability exists within the reading
of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A
specially crafted challenge packet can cause the program termination
leading to a denial of service condition. An attacker can compromise the
server or use man in the middle to trigger this vulnerability
(CVE-2017-2836).

An exploitable denial of service vulnerability exists within the
handling of security data in FreeRDP 2.0.0-beta1+android11. A specially
crafted challenge packet can cause the program termination leading to a
denial of service condition. An attacker can compromise the server or
use man in the middle to trigger this vulnerability (CVE-2017-2837).

An exploitable denial of service vulnerability exists within the
handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A
specially crafted challenge packet can cause the program termination
leading to a denial of service condition. An attacker can compromise the
server or use man in the middle to trigger this vulnerability
(CVE-2017-2838, CVE-2017-2839).

Affected Software/OS:
'freerdp' package(s) on Mageia 5.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-2834
BugTraq ID: 99942
http://www.securityfocus.com/bid/99942
Debian Security Information: DSA-3923 (Google Search)
https://www.debian.org/security/2017/dsa-3923
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0336
Common Vulnerability Exposure (CVE) ID: CVE-2017-2835
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0337
Common Vulnerability Exposure (CVE) ID: CVE-2017-2836
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0338
Common Vulnerability Exposure (CVE) ID: CVE-2017-2837
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0339
Common Vulnerability Exposure (CVE) ID: CVE-2017-2838
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0340
Common Vulnerability Exposure (CVE) ID: CVE-2017-2839
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0341
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.