Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2018.0214
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2018-0214)
Resumen:The remote host is missing an update for the 'libofx' package(s) announced via the MGASA-2018-0214 advisory.
Descripción:Summary:
The remote host is missing an update for the 'libofx' package(s) announced via the MGASA-2018-0214 advisory.

Vulnerability Insight:
An exploitable buffer overflow vulnerability exists in the tag parsing
functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a
write out of bounds resulting in a buffer overflow on the stack. An
attacker can construct a malicious OFX file to trigger this
vulnerability (CVE-2017-2816).

An exploitable buffer overflow vulnerability exists in the tag parsing
functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a
write out of bounds resulting in a buffer overflow on the stack. An
attacker can construct a malicious OFX file to trigger this
vulnerability (CVE-2017-2920).

ofx_proc_file in ofx_preproc.cpp in LibOFX 0.9.12 allows remote
attackers to cause a denial of service (heap-based buffer over-read and
application crash) via a crafted file, as demonstrated by an ofxdump
call (CVE-2017-14731).

Affected Software/OS:
'libofx' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-14731
https://security.gentoo.org/glsa/201908-26
https://github.com/libofx/libofx/issues/10
https://lists.debian.org/debian-lts-announce/2017/11/msg00038.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-2816
BugTraq ID: 100828
http://www.securityfocus.com/bid/100828
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0317
Common Vulnerability Exposure (CVE) ID: CVE-2017-2920
BugTraq ID: 101186
http://www.securityfocus.com/bid/101186
https://github.com/libofx/libofx/commit/a70934eea95c76a7737b83773bffe8738935082d
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0427
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.