PT-2009-6671 · Debian · Yaws+5

Praveen Darshanam

·

Publicado

1970-01-01

·

Atualizado

2017-09-29

·

CVE-2009-0751

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions yaws versions prior to 1.80 yaws-chat (affected versions not specified) yaws-wiki (affected versions not specified) yaws-yapp (affected versions not specified) yaws-mail (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the yaws package of the Debian GNU/Linux operating system, which can lead to a disruption of protected information. These vulnerabilities can be exploited remotely. According to the information, a request with a large number of headers can cause a denial of service, resulting in memory consumption and a crash.
Recommendations For yaws versions prior to 1.80, update to version 1.80 or later to resolve the issue. For yaws-chat, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For yaws-wiki, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For yaws-yapp, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For yaws-mail, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01931
BDU:2015-01932
BDU:2015-01933
BDU:2015-01934
BDU:2015-01935
CVE-2009-0751
DSA-1740-1

Produtos afetados

Debian
Yaws
Yaws-Chat
Yaws-Mail
Yaws-Wiki
Yaws-Yapp