Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.56472
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1020-1)
Summary:The remote host is missing an update for the Debian 'flex' package(s) announced via the DSA-1020-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'flex' package(s) announced via the DSA-1020-1 advisory.

Vulnerability Insight:
Chris Moore discovered that flex, a scanner generator, generates code, which allocates insufficient memory, if the grammar contains REJECT statements or trailing context rules. This may lead to a buffer overflow and the execution of arbitrary code.

If you use code, which is derived from a vulnerable lex grammar in an untrusted environment you need to regenerate your scanner with the fixed version of flex.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in version 2.5.31-31sarge1.

For the unstable distribution (sid) this problem has been fixed in version 2.5.33-1.

We recommend that you upgrade your flex package.

Affected Software/OS:
'flex' package(s) on Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-0459
16896
http://www.securityfocus.com/bid/16896
19071
http://secunia.com/advisories/19071
19126
http://secunia.com/advisories/19126
19228
http://secunia.com/advisories/19228
19424
http://secunia.com/advisories/19424
23440
http://www.osvdb.org/23440
570
http://securityreason.com/securityalert/570
ADV-2006-0770
http://www.vupen.com/english/advisories/2006/0770
DSA-1020
http://www.us.debian.org/security/2006/dsa-1020
GLSA-200603-07
http://www.gentoo.org/security/en/glsa/glsa-200603-07.xml
USN-260-1
https://usn.ubuntu.com/260-1/
[flex-announce] 20060222 flex 2.5.33 released
http://sourceforge.net/mailarchive/forum.php?thread_name=20060223020346.GA11231%40tabitha.home.tldz.org&forum_name=flex-announce
flex-bypass-security(24995)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24995
http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.