Train

PDA

توجه ! این یک نسخه آرشیو شده میباشد و در این حالت شما عکسی را مشاهده نمیکنید برای مشاهده کامل متن و عکسها بر روی لینک مقابل کلیک کنید : SnapGear Release Candidate Fixes Multiple Vulnerabilities


NI3
11-04-2003, 12:24 PM
hi :
----------
TITLE:
SnapGear Release Candidate Fixes Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA10117

VERIFY ADVISORY:
[Only registered and activated users can see links]

CRITICAL:
Highly critical

IMPACT:
DoS, System access

WHERE:
From remote

OPERATING SYSTEM:
SnapGear 1.x

DESCRIPTION:
SnapGear has issued a release candidate, which fixes several
vulnerabilities. These can potentially be exploited by malicious
people to cause a DoS (Denial of Service) or compromise a vulnerable
device.

For more information:
SA9429
SA9743
SA9886

SOLUTION:
SnapGear has issued a release candidate (version 1.8.5).
[Only registered and activated users can see links]

OTHER REFERENCES:
SA9429:
[Only registered and activated users can see links]

SA9743:
[Only registered and activated users can see links]

SA9886:
[Only registered and activated users can see links]

----------------------------------------------------------------------

NI3
11-04-2003, 12:26 PM
hi
------------
TITLE:
Serious Engine Malformed Client Packet Denial of Service
Vulnerability

SECUNIA ADVISORY ID:
SA10090

VERIFY ADVISORY:
[Only registered and activated users can see links]

CRITICAL:
Less critical

IMPACT:
DoS

WHERE:
From remote

SOFTWARE:
Serious Engine 1.x

DESCRIPTION:
A vulnerability has been reported in Serious Engine, which can be
exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error when handling client
data. This can be exploited by sending a specially crafted packet to
a server, which causes it to crash or hang.

The following products are reportedly affected:
* Serious Sam: the First Encounter (version 1.05 and prior)
* Serious Sam: the Second Encounter (version 1.05 and prior)
* Demos of Serious Sam (version 2 2.1a and the demo of the Second
Encounter)

SOLUTION:
Version 1.07 is not vulnerable.

REPORTED BY / CREDITS:
Luigi Auriemma

ORIGINAL ADVISORY:
[Only registered and activated users can see links]

----------------------------------------------------------------------