Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51893
Category:Ubuntu Local Security Checks
Title:Ubuntu 4.10 USN-98-1 (openslp)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to openslp
announced via advisory USN-98-1.

The SuSE Security Team discovered several buffer overflows in the
OpenSLP server and client library. By sending specially crafted SLP
packets, a remote attacker could exploit this to crash the SLP server
or execute arbitrary code with the privileges of the daemon user.
Likewise, a malicious SLP server could exploit the client library
vulnerabilities to execute arbitrary code with the privileges of the
user running the SLP client application.

The following packages are affected:

libslp1
slpd

Solution:
The problem can be corrected by upgrading the affected package to
version 1.0.11-7ubuntu0.1. In general, a standard system upgrade is
sufficient to effect the necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-98-1
http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032534.html

Risk factor : High

CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.