Executive Summary
Summary | |
---|---|
Title | Perl vulnerability |
Informations | |||
---|---|---|---|
Name | USN-794-1 | First vendor Publication | 2009-07-02 |
Vendor | Ubuntu | Last vendor Modification | 2009-07-02 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: Ubuntu 8.10: Ubuntu 9.04: In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that the Compress::Raw::Zlib Perl module incorrectly handled certain zlib compressed streams. If a user or automated system were tricked into processing a specially crafted compressed stream or file, a remote attacker could crash the application, leading to a denial of service. |
Original Source
Url : http://www.ubuntu.com/usn/USN-794-1 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-189 | Numeric Errors (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:13328 | |||
Oval ID: | oval:org.mitre.oval:def:13328 | ||
Title: | USN-794-1 -- libcompress-raw-zlib-perl, perl vulnerability | ||
Description: | It was discovered that the Compress::Raw::Zlib Perl module incorrectly handled certain zlib compressed streams. If a user or automated system were tricked into processing a specially crafted compressed stream or file, a remote attacker could crash the application, leading to a denial of service. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-794-1 CVE-2009-1391 | Version: | 5 |
Platform(s): | Ubuntu 8.10 Ubuntu 8.04 Ubuntu 9.04 | Product(s): | libcompress-raw-zlib-perl perl |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-12-10 | Name : Mandriva Security Advisory MDVSA-2009:157-1 (perl-Compress-Raw-Zlib) File : nvt/mdksa_2009_157_1.nasl |
2009-10-11 | Name : SLES11: Security update for Perl File : nvt/sles11_perl.nasl |
2009-09-02 | Name : Fedora Core 11 FEDORA-2009-8868 (perl-Compress-Raw-Bzip2) File : nvt/fcore_2009_8868.nasl |
2009-09-02 | Name : Fedora Core 10 FEDORA-2009-8888 (perl-Compress-Raw-Bzip2) File : nvt/fcore_2009_8888.nasl |
2009-09-02 | Name : Gentoo Security Advisory GLSA 200908-07 (Compress-Raw-Zlib Compress-Raw-Bzip2) File : nvt/glsa_200908_07.nasl |
2009-09-02 | Name : Mandrake Security Advisory MDVSA-2009:207 (perl-Compress-Raw-Bzip2) File : nvt/mdksa_2009_207.nasl |
2009-08-17 | Name : Mandrake Security Advisory MDVSA-2009:174 (perl-Compress-Raw-Zlib) File : nvt/mdksa_2009_174.nasl |
2009-07-29 | Name : Fedora Core 10 FEDORA-2009-7680 (perl) File : nvt/fcore_2009_7680.nasl |
2009-07-29 | Name : Mandrake Security Advisory MDVSA-2009:157 (perl-Compress-Raw-Zlib) File : nvt/mdksa_2009_157.nasl |
2009-07-29 | Name : Ubuntu USN-805-1 (ruby1.9) File : nvt/ubuntu_805_1.nasl |
2009-07-06 | Name : SuSE Security Summary SUSE-SR:2009:012 File : nvt/suse_sr_2009_012.nasl |
2009-07-06 | Name : Ubuntu USN-794-1 (perl) File : nvt/ubuntu_794_1.nasl |
2009-06-23 | Name : Fedora Core 11 FEDORA-2009-6033 (perl) File : nvt/fcore_2009_6033.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
55041 | Perl Compress::Raw::Zlib Module Zlib.xs inflate() Function Overflow |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-07-30 | Name : The remote Mandriva Linux host is missing a security update. File : mandriva_MDVSA-2009-207.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_perl-090610.nasl - Type : ACT_GATHER_INFO |
2009-08-24 | Name : The remote Fedora host is missing a security update. File : fedora_2009-8868.nasl - Type : ACT_GATHER_INFO |
2009-08-24 | Name : The remote Fedora host is missing a security update. File : fedora_2009-8888.nasl - Type : ACT_GATHER_INFO |
2009-08-20 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200908-07.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_perl-090610.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_perl-090610.nasl - Type : ACT_GATHER_INFO |
2009-07-20 | Name : The remote Mandriva Linux host is missing a security update. File : mandriva_MDVSA-2009-157.nasl - Type : ACT_GATHER_INFO |
2009-07-17 | Name : The remote Fedora host is missing a security update. File : fedora_2009-7680.nasl - Type : ACT_GATHER_INFO |
2009-07-03 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-794-1.nasl - Type : ACT_GATHER_INFO |
2009-06-24 | Name : The remote openSUSE host is missing a security update. File : suse_perl-Compress-Raw-Zlib-6300.nasl - Type : ACT_GATHER_INFO |
2009-06-16 | Name : The remote Fedora host is missing a security update. File : fedora_2009-6033.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 12:06:03 |
|