Description: | Description:
The remote host is missing updates announced in advisory TSLSA-2007-0019.
fetchmail < TSL 3.0.5 > < TSL 3.0 > - New upsteam. - SECURITY Fix: A weakness has been identified which is caused by an error in the APOP protocol that fails to properly prevent MD5 collisions, which could be exploited via man-in-the-middle attacks and specially crafted message-IDs to potentially disclose the first three characters of passwords.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2007-1558 to this issue.
freetype < TSL 3.0.5 > < TSL 3.0 > < TSL 2.2 > - SECURITY Fix: Victor Stinner has reported a vulnerability in FreeType, caused due to an error when parsing malformed TTF fonts in src/truetype/ttgload.c and may be exploited when processing a specially crafted TTF font.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2007-2754 to this issue.
gd < TSL 3.0.5 > < TSL 3.0 > < TSL 2.2 > - SECURITY Fix: Xavier Roche has reported a vulnerability in GD Graphics Library caused due to the incorrect use of libpng within the function gdPngReadData() when processing truncated data. This can be exploited to cause an infinite loop by e.g. tricking an application using the library to process a specially crafted file.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2007-2756 to this issue.
libpng < TSL 3.0.5 > < TSL 3.0 >< TSL 2.2 > < TSEL 2> - SECURITY Fix: A vulnerability has been reported in libpng, caused due to an error in the png_handle_tRNS function in pngrutil.c. This can be exploited by tricking an application using the library to process a specially crafted PNG file containing a malformed tRNS chunk.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2007-2445 to this issue.
python24 < TSL 3.0.5 > - SECURITY Fix: A vulnerability has been identified, which could be exploited by attackers to gain knowledge of potentially sensitive information. This issue is caused by an off-by-one error in the PyLocale_strxfrm() [Modules/_localemodule.c] function when calculating the n2 buffer size, which could be exploited by attackers to disclose and read portions of memory.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2007-2052 to this issue.
Solution: Update your system with the packages as indicated in the referenced security advisory.
http://www.securityspace.com/smysecure/catid.html?in=TSLSA-2007-0019
Risk factor : High
CVSS Score: 6.8
|