Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2018.0025
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2018-0025)
Resumen:The remote host is missing an update for the 'gvfs, ifuse, kodi, libgpod, libimobiledevice, libplist, upower, usbmuxd' package(s) announced via the MGASA-2018-0025 advisory.
Descripción:Summary:
The remote host is missing an update for the 'gvfs, ifuse, kodi, libgpod, libimobiledevice, libplist, upower, usbmuxd' package(s) announced via the MGASA-2018-0025 advisory.

Vulnerability Insight:
The base64decode function in libplist allowed attackers to obtain
sensitive information from process memory or cause a denial of
service (buffer over-read) via split encoded Apple Property List data
(CVE-2017-5209).

The main function in plistutil.c in libimobiledevice libplist allowed
attackers to obtain sensitive information from process memory or cause a
denial of service (buffer over-read) via Apple Property List data that is
too short (CVE-2017-5545).

A heap-buffer overflow in parse_dict_node could cause a segmentation fault
(CVE-2017-5834).

Malicious crafted file could cause libplist to allocate large amounts of
memory and consume lots of CPU because of a memory allocation error
(CVE-2017-5835).

A type inconsistency in bplist.c could cause the application to crash
(CVE-2017-5836).

Crafted plist file could lead to Heap-buffer overflow (CVE-2017-6435).

Integer overflow in parse_string_node (CVE-2017-6436).

The base64encode function in base64.c allows local users to cause denial
of service (out-of-bounds read) via a crafted plist file (CVE-2017-6437).

Heap-based buffer overflow in the parse_unicode_node function
(CVE-2017-6438).

Heap-based buffer overflow in the parse_string_node function
(CVE-2017-6439).

Ensure that sanity checks work on 32-bit platforms (CVE-2017-6440).

Add some safety checks, backported from upstream (CVE-2017-7982).

The gvfs, ifuse, kodi, libgpod, libimobiledevice, upower, and usbmuxd
packages have been rebuilt for the updated libplist.

Affected Software/OS:
'gvfs, ifuse, kodi, libgpod, libimobiledevice, libplist, upower, usbmuxd' package(s) on Mageia 5.

Solution:
Please install the updated package(s).

CVSS Score:
6.4

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-5209
BugTraq ID: 95385
http://www.securityfocus.com/bid/95385
https://lists.debian.org/debian-lts-announce/2020/04/msg00002.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-5545
BugTraq ID: 95702
http://www.securityfocus.com/bid/95702
Common Vulnerability Exposure (CVE) ID: CVE-2017-5834
BugTraq ID: 96022
http://www.securityfocus.com/bid/96022
http://www.openwall.com/lists/oss-security/2017/01/31/6
http://www.openwall.com/lists/oss-security/2017/02/02/4
Common Vulnerability Exposure (CVE) ID: CVE-2017-5835
Common Vulnerability Exposure (CVE) ID: CVE-2017-5836
Common Vulnerability Exposure (CVE) ID: CVE-2017-6435
BugTraq ID: 97586
http://www.securityfocus.com/bid/97586
https://github.com/libimobiledevice/libplist/issues/93
Common Vulnerability Exposure (CVE) ID: CVE-2017-6436
BugTraq ID: 97290
http://www.securityfocus.com/bid/97290
https://github.com/libimobiledevice/libplist/issues/94
Common Vulnerability Exposure (CVE) ID: CVE-2017-6437
BugTraq ID: 97291
http://www.securityfocus.com/bid/97291
https://github.com/libimobiledevice/libplist/issues/100
Common Vulnerability Exposure (CVE) ID: CVE-2017-6438
BugTraq ID: 97281
http://www.securityfocus.com/bid/97281
https://github.com/libimobiledevice/libplist/issues/98
Common Vulnerability Exposure (CVE) ID: CVE-2017-6439
BugTraq ID: 97278
http://www.securityfocus.com/bid/97278
https://github.com/libimobiledevice/libplist/issues/95
Common Vulnerability Exposure (CVE) ID: CVE-2017-6440
BugTraq ID: 97583
http://www.securityfocus.com/bid/97583
https://github.com/libimobiledevice/libplist/issues/99
Common Vulnerability Exposure (CVE) ID: CVE-2017-7982
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.