French Security Incident Response Team

FrSIRT   

      

   français French  anglais English

 
Vulnerability Notification Service
FrSIRT Partner Program
14-Day Free Trial
Contact FrSIRT Sales Dept.
 

Security Advisories
Linux Security Advisories
Virus and Threats Advisories
Latest Security News
Latest Zero Day Threats
Advisories and vulnerabilities by Vendor
Advisories and vulnerabilities by Keyword
 

Report a security incident
Report a new vulnerability
Security Mailinglist
 

Our Company
FrSIRT in the News
Advertise on FrSIRT.COM
Security Researchers and Exploit Writers Jobs
Contact Us

Mandriva Security Update Fixes Boost Denial of Service Vulnerabilities


Title : Mandriva Security Update Fixes Boost Denial of Service Vulnerabilities
Advisory ID : FrSIRT/ADV-2008-0381
CVE ID : CVE-2008-0171 - CVE-2008-0172
Rated as : Low Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2008-02-04

Advisory Details

 
  Description
  Affected Products
  Solution
  References
Technical Description    Receive FrSIRT alerts in a Text format  Receive FrSIRT alerts in a PDF format  Receive FrSIRT alerts in an XML format  Receive FrSIRT notifications by SMS 

Multiple vulnerabilities have been idenitified in Mandriva, which could be exploited by attackers to cause a denial of service [...]

Solution

Upgrade the affected packages :

Mandriva Linux 2007.0:
050747f9a2c9557d33977d9bd51184b2 2007.0/i586/libboost1-1.33.1-3.1mdv2007.0.i586.rpm
447ac5fc34d29669c8a21b7abd677413 2007.0/i586/libboost1-devel-1.33.1-3.1mdv2007.0.i586.rpm
4b4b7ff3d032516cd2f22af208ef7d3b 2007.0/i586/libboost1-examples-1.33.1-3.1mdv2007.0.i586.rpm
b084ed15b24c16e41ea2660732d1fa53 2007.0/i586/libboost1-static-devel-1.33.1-3.1mdv2007.0.i586.rpm
4b9252988703c7360d91138aa1b738b7 2007.0/SRPMS/boost-1.33.1-3.1mdv2007.0.src.rpm

Mandriva Linux 2007.0/X86_64:
9b983d8a118824218998792630a93368 2007.0/x86_64/lib64boost1-1.33.1-3.1mdv2007.0.x86_64.rpm
f975c8790f99728dd3635b0a79a2b639 2007.0/x86_64/lib64boost1-devel-1.33.1-3.1mdv2007.0.x86_64.rpm
8349cb46e64007d854902abe784278d8 2007.0/x86_64/lib64boost1-examples-1.33.1-3.1mdv2007.0.x86_64.rpm
8781b8e9cac3079e22be542dc89679e0 2007.0/x86_64/lib64boost1-static-devel-1.33.1-3.1mdv2007.0.x86_64.rpm
4b9252988703c7360d91138aa1b738b7 2007.0/SRPMS/boost-1.33.1-3.1mdv2007.0.src.rpm

Mandriva Linux 2007.1:
4e2b108f19e9e77cacd23f950a287c1a 2007.1/i586/libboost1-1.33.1-5.1mdv2007.1.i586.rpm
953ecb0bb51516d5a860947c6ec3cca3 2007.1/i586/libboost1-devel-1.33.1-5.1mdv2007.1.i586.rpm
cec00f6e2461c188e12248ec1085b64a 2007.1/i586/libboost1-examples-1.33.1-5.1mdv2007.1.i586.rpm
7f3150b483155ba9ddc5ce9b9c6a24b1 2007.1/i586/libboost1-static-devel-1.33.1-5.1mdv2007.1.i586.rpm
0133bec4e45c53c26b59fe599b0c2ef3 2007.1/SRPMS/boost-1.33.1-5.1mdv2007.1.src.rpm

Mandriva Linux 2007.1/X86_64:
55150e1ce05e3d3385815648cd4924ba 2007.1/x86_64/lib64boost1-1.33.1-5.1mdv2007.1.x86_64.rpm
93d7474def1e122c4ddf5fab1e81dfd6 2007.1/x86_64/lib64boost1-devel-1.33.1-5.1mdv2007.1.x86_64.rpm
59dd3438007e7d383d3cbaa1b2eacb38 2007.1/x86_64/lib64boost1-examples-1.33.1-5.1mdv2007.1.x86_64.rpm
a213a0ee7cdc1b75fbbde6835a7295db 2007.1/x86_64/lib64boost1-static-devel-1.33.1-5.1mdv2007.1.x86_64.rpm
0133bec4e45c53c26b59fe599b0c2ef3 2007.1/SRPMS/boost-1.33.1-5.1mdv2007.1.src.rpm

Mandriva Linux 2008.0:
e184b23843e35d7365033cc6cb45f2dd 2008.0/i586/libboost1-1.33.1-6.1mdv2008.0.i586.rpm
6fa2ca96cb71d8bd3e54aa2f05118017 2008.0/i586/libboost1-devel-1.33.1-6.1mdv2008.0.i586.rpm
aa82d51548030d03ad1e86a174013333 2008.0/i586/libboost1-examples-1.33.1-6.1mdv2008.0.i586.rpm
42d0e230fca8ac7b094f9d159e9d8758 2008.0/i586/libboost1-static-devel-1.33.1-6.1mdv2008.0.i586.rpm
e4b3da7cdfb5210d65c5b60556e9744e 2008.0/SRPMS/boost-1.33.1-6.1mdv2008.0.src.rpm

Mandriva Linux 2008.0/X86_64:
af70bbe3671b92f97d09e845682609ca 2008.0/x86_64/lib64boost1-1.33.1-6.1mdv2008.0.x86_64.rpm
3597c04eea3dea15c278cdb3f0bbcc8e 2008.0/x86_64/lib64boost1-devel-1.33.1-6.1mdv2008.0.x86_64.rpm
65468c84027dbe61a43146a82a5a76e8 2008.0/x86_64/lib64boost1-examples-1.33.1-6.1mdv2008.0.x86_64.rpm
3a6b5ed6fffb8d18358729afb1f9ebc1 2008.0/x86_64/lib64boost1-static-devel-1.33.1-6.1mdv2008.0.x86_64.rpm
e4b3da7cdfb5210d65c5b60556e9744e 2008.0/SRPMS/boost-1.33.1-6.1mdv2008.0.src.rpm

ChangeLog

2008-02-04 : Initial release

Vulnerability Management

Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.


 
 

Search

      

Mailinglist

    
 

Cisco UCM SIP Remote Denial of Service

Cisco IOS Denial of Service and Security Bypass Vulnerabilities

Cisco PIX and ASA Information Disclosure and DoS Vulnerabilities

Cisco Secure ACS EAP Remote Denial Of Service Vulnerability

Cisco Products Remote DNS Cache Poisoning Vulnerability

Cisco Wide Area Application Services CUPS Remote Vulnerability

Cisco UCM Denial of Service and Authentication Bypass Vulnerabilities

Microsoft Windows Vista "WRITE_ANDX" Denial of Service Vulnerability

Microsoft Office OneNote URL Code Execution (MS08-055)

Microsoft GDI+ Multiple Code Execution Vulnerabilities (MS08-052)

Microsoft Visual Studio "Msmask32" Code Execution Vulnerability

Microsoft PowerPoint Command Execution Vulnerabilities (MS08-051)

Microsoft Windows Messenger Data Disclosure (MS08-050)

Microsoft Windows Event System Code Execution (MS08-049)

Oracle Products Multiple Code Execution and Security Bypass Issues

Oracle Products Command Execution and SQL Injection Vulnerabilities

Oracle Products Multiple Code Execution and SQL Injection Vulnerabilities

Oracle Database "PITRIG_DROPMETADATA" Buffer Overflow Vulnerability

Oracle Products Multiple Code Execution and SQL Injection Vulnerabilities

Oracle JInitiator ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities

Oracle Products Multiple Remote Command Execution and SQL Injection Vulnerabilities

Copyright 2003-2008 © FrSIRT.COM - Privacy Policy