Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | |||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.880788 |
Categoría: | CentOS Local Security Checks |
Título: | CentOS Update for curl CESA-2009:1209 centos3 i386 |
Resumen: | The remote host is missing an update for the 'curl'; package(s) announced via the referenced advisory. |
Descripción: | Summary: The remote host is missing an update for the 'curl' package(s) announced via the referenced advisory. Vulnerability Insight: cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict servers, using any of the supported protocols. cURL is designed to work without user interaction or any kind of interactivity. Scott Cantor reported that cURL is affected by the previously published 'null prefix attack', caused by incorrect handling of NULL characters in X.509 certificates. If an attacker is able to get a carefully-crafted certificate signed by a trusted Certificate Authority, the attacker could use the certificate during a man-in-the-middle attack and potentially confuse cURL into accepting it by mistake. (CVE-2009-2417) cURL users should upgrade to these updated packages, which contain a backported patch to correct these issues. All running applications using libcurl must be restarted for the update to take effect. Affected Software/OS: curl on CentOS 3 Solution: Please install the updated packages. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-2417 http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html BugTraq ID: 36032 http://www.securityfocus.com/bid/36032 Bugtraq: 20090824 rPSA-2009-0124-1 curl (Google Search) http://www.securityfocus.com/archive/1/506055/100/0/threaded Bugtraq: 20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components (Google Search) http://www.securityfocus.com/archive/1/507985/100/0/threaded https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10114 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8542 http://secunia.com/advisories/36238 http://secunia.com/advisories/36475 http://secunia.com/advisories/37471 http://secunia.com/advisories/45047 http://www.ubuntu.com/usn/USN-1158-1 http://www.vupen.com/english/advisories/2009/2263 http://www.vupen.com/english/advisories/2009/3316 XForce ISS Database: curl-certificate-security-bypass(52405) https://exchange.xforce.ibmcloud.com/vulnerabilities/52405 |
Copyright | Copyright (c) 2011 Greenbone Networks GmbH |
Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |