Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.880796
Categoría:CentOS Local Security Checks
Título:CentOS Update for finch CESA-2009:1139 centos5 i386
Resumen:The remote host is missing an update for the 'finch'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'finch'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. The AOL
Open System for CommunicAtion in Realtime (OSCAR) protocol is used by the
AOL ICQ and AIM instant messaging systems.

A denial of service flaw was found in the Pidgin OSCAR protocol
implementation. If a remote ICQ user sent a web message to a local Pidgin
user using this protocol, it would cause excessive memory usage, leading to
a denial of service (Pidgin crash). (CVE-2009-1889)

These updated packages also fix the following bug:

* the Yahoo! Messenger Protocol changed, making it incompatible (and
unusable) with Pidgin versions prior to 2.5.7. This update provides Pidgin
2.5.8, which implements version 16 of the Yahoo! Messenger Protocol, which
resolves this issue.

Note: These packages upgrade Pidgin to version 2.5.8. Refer to the linked Pidgin
release notes for a full list of changes.

All Pidgin users should upgrade to these updated packages, which correct
these issues. Pidgin must be restarted for this update to take effect.

Affected Software/OS:
finch on CentOS 5

Solution:
Please install the updated packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-1889
BugTraq ID: 35530
http://www.securityfocus.com/bid/35530
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00162.html
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00176.html
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00228.html
http://pidgin.im/pipermail/devel/2009-May/008227.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10004
http://www.redhat.com/support/errata/RHSA-2009-1139.html
http://secunia.com/advisories/35693
http://secunia.com/advisories/35697
http://secunia.com/advisories/35706
http://secunia.com/advisories/37071
http://www.ubuntu.com/usn/USN-796-1
http://www.vupen.com/english/advisories/2009/1749
XForce ISS Database: pidgin-oscar-dos(51448)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51448
CopyrightCopyright (c) 2011 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.