⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 deb_163_1.nasl

📁 漏洞扫描源码,可以扫描linux,windows,交换机路由器
💻 NASL
字号:
# OpenVAS Vulnerability Test# $Id$# Description: Auto-generated from advisory DSA 163-1## Authors:# Thomas Reinke <reinke@securityspace.com>## Copyright:# Copyright (c) 2007 E-Soft Inc. http://www.securityspace.com# Text descriptions are largerly excerpted from the referenced# advisory, and are Copyright (c) the respective author(s)## This program is free software; you can redistribute it and/or modify# it under the terms of the GNU General Public License version 2,# as published by the Free Software Foundation## This program is distributed in the hope that it will be useful,# but WITHOUT ANY WARRANTY; without even the implied warranty of# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the# GNU General Public License for more details.## You should have received a copy of the GNU General Public License# along with this program; if not, write to the Free Software# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.#if(description){ script_id(53731); script_cve_id("CVE-2002-0738"); script_bugtraq_id(4546); script_version ("$"); name["english"] = "Debian Security Advisory DSA 163-1 (mhonarc)"; script_name(english:name["english"]); desc["english"] = "The remote host is missing an update to mhonarcannounced via advisory DSA 163-1.Jason Molenda and Hiromitsu Takagi found ways to exploit cross sitescripting bugs in mhonarc, a mail to HTML converter.  When processingmaliciously crafted mails of type text/html, mhonarc, does notdeactivate all scripting parts properly.  This is fixed in upstreamversion 2.5.3.If you are worried about security, it is recommended that you disablesupport of text/html messages in your mail archives.  There is noguarantee that the mhtxthtml.pl library is robust enough to eliminateall possible exploits that can occur with HTML data.To exclude HTML data, you can use the MIMEEXCS resource.  For example:<MIMEExcs>text/htmltext/x-html</MIMEExcs>The use of text/x-html is probably not used any more, but is good toinclude it, just-in-case.If you are concerend that this could block out the entire contents ofsome messages, then you could do the following instead:<MIMEFilters>text/html; m2h_text_plain::filter; mhtxtplain.pltext/x-html; m2h_text_plain::filter; mhtxtplain.pl</MIMEFilters>This treats the HTML as text/plain.The above problems have been fixed in version 2.5.2-1.1 for thecurrent stable stable distribution (woody), in version 2.4.4-1.1 forthe old stable distribution (potato) and in version 2.5.11-1 for theunstable distribution (sid).We recommend that you upgrade your mhonarc packages.Solution:https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20163-1Risk factor : High"; script_description(english:desc["english"]); summary["english"] = "Debian Security Advisory DSA 163-1 (mhonarc)"; script_summary(english:summary["english"]); script_category(ACT_GATHER_INFO); script_copyright(english:"Copyright (c) 2005 E-Soft Inc. http://www.securityspace.com"); family["english"] = "Debian Local Security Checks"; script_family(english:family["english"]); script_dependencies("gather-package-list.nasl"); script_require_keys("ssh/login/packages"); exit(0);}## The script code starts here#include("revisions-lib.inc");include("pkg-lib-deb.inc");vuln = 0;if(isdpkgvuln(pkg:"mhonarc", ver:"2.4.4-1.1", rls:"DEB2.2")) {    vuln = 1;}if(isdpkgvuln(pkg:"mhonarc", ver:"2.5.2-1.1", rls:"DEB3.0")) {    vuln = 1;}if(vuln) {    security_hole(0);}

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -