Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.831722
Category:Mandrake Local Security Checks
Title:Mandriva Update for usbmuxd MDVSA-2012:133 (usbmuxd)
Summary:The remote host is missing an update for the 'usbmuxd'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'usbmuxd'
package(s) announced via the referenced advisory.

Vulnerability Insight:
It was discovered that usbmuxd did not correctly perform bounds
checking when processing the SerialNumber field of USB devices. An
attacker with physical access could use this to crash usbmuxd
or potentially execute arbitrary code as the 'usbmux' user
(CVE-2012-0065).

The updated packages have been patched to correct this issue.

Affected Software/OS:
usbmuxd on Mandriva Linux 2011.0

Solution:
Please Install the Updated Packages.

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-0065
47545
http://secunia.com/advisories/47545
51573
http://www.securityfocus.com/bid/51573
MDVSA-2012:133
http://www.mandriva.com/security/advisories?name=MDVSA-2012:133
MDVSA-2013:133
http://www.mandriva.com/security/advisories?name=MDVSA-2013:133
[oss-security] 20120119 CVE request: usbmuxd 1.0.7 "receive_packet()" Buffer Overflow Vulnerability
http://openwall.com/lists/oss-security/2012/01/19/25
[oss-security] 20120119 Re: CVE request: usbmuxd 1.0.7 "receive_packet()" Buffer Overflow Vulnerability
http://openwall.com/lists/oss-security/2012/01/19/26
http://git.marcansoft.com/?p=usbmuxd.git%3Ba=commitdiff%3Bh=f794991993af56a74795891b4ff9da506bc893e6
https://bugs.gentoo.org/show_bug.cgi?id=399409
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0228
usbmuxd-libusbmuxd-bo(72546)
https://exchange.xforce.ibmcloud.com/vulnerabilities/72546
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.