Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2018.0163
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2018-0163)
Resumen:The remote host is missing an update for the 'bctoolbox, dolphin-emu, hiawatha, mbedtls, shadowsocks-libev' package(s) announced via the MGASA-2018-0163 advisory.
Descripción:Summary:
The remote host is missing an update for the 'bctoolbox, dolphin-emu, hiawatha, mbedtls, shadowsocks-libev' package(s) announced via the MGASA-2018-0163 advisory.

Vulnerability Insight:
The mbedtls package has been updated to fix several security issues.

Fixed a heap corruption issue in the implementation of the truncated HMAC
extension. When the truncated HMAC extension is enabled and CBC is used,
sending a malicious application packet could be used to selectively corrupt
6 bytes on the peer's heap, which could potentially lead to crash or remote
code execution. The issue could be triggered remotely from either side in
both TLS and DTLS. (CVE-2018-0488)

Fixed a buffer overflow in RSA-PSS verification when the hash was too large
for the key size, which could potentially lead to crash or remote code
execution. (CVE-2018-0487)

Affected Software/OS:
'bctoolbox, dolphin-emu, hiawatha, mbedtls, shadowsocks-libev' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2018-0487
BugTraq ID: 103056
http://www.securityfocus.com/bid/103056
Debian Security Information: DSA-4138 (Google Search)
https://www.debian.org/security/2018/dsa-4138
Debian Security Information: DSA-4147 (Google Search)
https://www.debian.org/security/2018/dsa-4147
https://security.gentoo.org/glsa/201804-19
https://usn.ubuntu.com/4267-1/
Common Vulnerability Exposure (CVE) ID: CVE-2018-0488
BugTraq ID: 103057
http://www.securityfocus.com/bid/103057
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.