|
|
Vulnerability Assessment & Network Security Forums |
|||||||||
|
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA228] DSA-228-1 libmcrypt Vulnerability Assessment Details
|
[DSA228] DSA-228-1 libmcrypt |
||
|
DSA-228-1 libmcrypt Detailed Explanation for this Vulnerability Assessment Ilia Alshanetsky discovered several buffer overflows in libmcrypt, a decryption and encryption library, that originates from improper or lacking input validation. By passing input which is longer than expected to a number of functions (multiple functions are affected) the user can successfully make libmcrypt crash and may be able to insert arbitrary, malicious code which will be executed under the user libmcrypt runs as, e.g. inside a web server. Another vulnerability exists in the way libmcrypt loads algorithms via libtool. When different algorithms are loaded dynamically, each time an algorithm is loaded a small part of memory is leaked. In a persistent environment (web server) this could lead to a memory exhaustion attack that will exhaust all available memory by launching repeated requests at an application utilizing the mcrypt library. For the current stable distribution (woody) these problems have been fixed in version 2.5.0-1woody1. The old stable distribution (potato) does not contain libmcrypt packages. For the unstable distribution (sid) these problems have been fixed in version 2.5.5-1. We recommend that you upgrade your libmcrypt packages. Solution : http://www.debian.org/security/2003/dsa-228 Network Security Threat Level: High Networks Security ID: 6510, 6512 Vulnerability Assessment Copyright: This script is (C) 2005 Michel Arboi |
||
|
Cables, Connectors |

(New) AMD Ryzen 7 5700X 8 Core 16 Thread AM4 Unlocked 3.4 GHz CPU OEM Tray
$174.99
SGIN 17.3" Laptop Intel Quad-Core Up to 2.4 GHZ 8GB RAM 256GB SSD HD
$229.99
Microsoft Surface Pro 5 Silver 128GB SSD 4gb RAM
$97.97
Lenovo IdeaPad S340-15IWL Laptop 15.6" Intel Core i3-8145U 8GB RAM 256GB SSD
$126.65
Intel Xeon E5 - 2667V2 / SR19W 3.30GHz 25MB 8-Core CPU Socket LGA2011
$30.00
AMD FX 8350 8-CORE 4.00GHz CPU FD8350FRW8KHK SOCKET AM3+ *QTY
$39.99
AMD Ryzen 7 5700G 8-Core 16-Thread 4.6GHz Max Boost, 3.8 GHz Base
$170.00
AMD Ryzen 7 9700X 8-Core 16-Thread 40MB Cache Socket AM5 9000 Series Processor
$245.99
Dell T7810 Workstation 8-Core 2.40GHz E5-2630 v3 No RAM GPU HDD OS
$259.98
Lenovo ThinkStation P520 Intel Xeon W-2245 8-Core 3.90GHz - NO RAM/ GPU/ HDD/ OS
$359.98
|
||
|
No Discussions have been posted on this vulnerability. |