Synopsis
The remote Mandriva Linux host is missing one or more security updates.
Description
Multiple vulnerabilities was discovered and corrected in silc-toolkit :
Multiple format string vulnerabilities in lib/silcclient/client_entry.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client before 1.1.8, allow remote attackers to execute arbitrary code via format string specifiers in a nickname field, related to the (1) silc_client_add_client, (2) silc_client_update_client, and (3) silc_client_nickname_format functions (CVE-2009-3051).
The silc_asn1_encoder function in lib/silcasn1/silcasn1_encode.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.8 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted OID value, related to incorrect use of a %lu format string (CVE-2008-7159).
The silc_http_server_parse function in lib/silchttp/silchttpserver.c in the internal HTTP server in silcd in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.9 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted Content-Length header, related to incorrect use of a %lu format string (CVE-2008-7160).
Multiple format string vulnerabilities in lib/silcclient/command.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client 1.1.8 and earlier, allow remote attackers to execute arbitrary code via format string specifiers in a channel name, related to (1) silc_client_command_topic, (2) silc_client_command_kick, (3) silc_client_command_leave, and (4) silc_client_command_users (CVE-2009-3163).
This update provides a solution to these vulnerabilities.
Update :
Packages for MES5 was not provided previousely, this update addresses this problem.
Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers
Solution
Update the affected packages.
Plugin Details
File Name: mandriva_MDVSA-2009-234.nasl
Supported Sensors: Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Vulnerability Information
CPE: p-cpe:/a:mandriva:linux:lib64silc-1.1_2, p-cpe:/a:mandriva:linux:lib64silcclient-1.1_2, p-cpe:/a:mandriva:linux:libsilc-1.1_2, p-cpe:/a:mandriva:linux:libsilcclient-1.1_2, p-cpe:/a:mandriva:linux:silc-toolkit, p-cpe:/a:mandriva:linux:silc-toolkit-devel, cpe:/o:mandriva:linux:2008.0
Required KB Items: Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list, Host/local_checks_enabled
Exploit Ease: No known exploits are available
Patch Publication Date: 12/5/2009