![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.60714 |
Category: | Red Hat Local Security Checks |
Title: | RedHat Security Advisory RHSA-2008:0131 |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing updates announced in advisory RHSA-2008:0131. The netpbm package contains a library of functions for editing and converting between various graphics file formats, including .pbm (portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable pixmaps) and others. The package includes no interactive tools and is primarily used by other programs (eg CGI scripts that manage web-site images). An input validation flaw was discovered in the GIF-to-PNM converter (giftopnm) shipped with the netpbm package. An attacker could create a carefully crafted GIF file which could cause giftopnm to crash or possibly execute arbitrary code as the user running giftopnm. (CVE-2008-0554) All users are advised to upgrade to these updated packages which contain a backported patch which resolves this issue. Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date http://rhn.redhat.com/errata/RHSA-2008-0131.html http://www.redhat.com/security/updates/classification/#moderate Risk factor : High CVSS Score: 6.8 |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-0554 1019358 http://www.securitytracker.com/id?1019358 27682 http://www.securityfocus.com/bid/27682 29079 http://secunia.com/advisories/29079 30280 http://secunia.com/advisories/30280 32607 http://secunia.com/advisories/32607 ADV-2008-0460 http://www.vupen.com/english/advisories/2008/0460 DSA-1579 http://www.debian.org/security/2008/dsa-1579 MDVSA-2008:039 http://www.mandriva.com/security/advisories?name=MDVSA-2008:039 RHSA-2008:0131 http://www.redhat.com/support/errata/RHSA-2008-0131.html USN-665-1 http://ubuntu.com/usn/usn-665-1 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464056 https://issues.rpath.com/browse/RPL-2216 oval:org.mitre.oval:def:10975 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10975 |
Copyright | Copyright (c) 2008 E-Soft Inc. http://www.securityspace.com |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |