Executive Summary
Summary | |
---|---|
Title | NAS vulnerabilities |
Informations | |||
---|---|---|---|
Name | USN-446-1 | First vendor Publication | 2007-03-28 |
Vendor | Ubuntu | Last vendor Modification | 2007-03-28 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: Ubuntu 6.06 LTS: Ubuntu 6.10: In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Luigi Auriemma discovered multiple flaws in the Network Audio System server. Remote attackers could send specially crafted network requests that could lead to a denial of service or execution of arbitrary code. Note that default Ubuntu installs do not include the NAS server. |
Original Source
Url : http://www.ubuntu.com/usn/USN-446-1 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2009-04-09 | Name : Mandriva Update for nas MDKSA-2007:065 (nas) File : nvt/gb_mandriva_MDKSA_2007_065.nasl |
2009-03-23 | Name : Ubuntu Update for nas vulnerabilities USN-446-1 File : nvt/gb_ubuntu_USN_446_1.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200704-20 (NAS) File : nvt/glsa_200704_20.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1273-1 (nas) File : nvt/deb_1273_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
34262 | Network Audio System (NAS) server/os/io.c ReadRequestFromClient Function NULL... |
34261 | Network Audio System (NAS) Multiple Array Index Error DoS |
34260 | Network Audio System (NAS) server/dia/resource.c AddResource Function Remote DoS |
34259 | Network Audio System (NAS) server/dia/audispatch.c ProcAuWriteElement Functio... |
34258 | Network Audio System (NAS) server/os/connection.c accept_att_local Function R... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-446-1.nasl - Type : ACT_GATHER_INFO |
2007-04-30 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200704-20.nasl - Type : ACT_GATHER_INFO |
2007-04-05 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1273.nasl - Type : ACT_GATHER_INFO |
2007-03-26 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-065.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 12:04:17 |
|