Debian DLA-117-1:qt4-x11 安全更新

high Nessus 插件 ID 82100

简介

远程 Debian 主机缺少安全更新。

描述

CVE-2011-3193

在 Lookup_MarkMarkPos 中检查可能导致具有某些字体的此函数中发生崩溃的缓冲区溢出。

CVE-2011-3194

修复 tiff 阅读器以处理灰度图像的 TIFFTAG_SAMPLESPERPIXEL。该阅读器使用 QImage::Format_Indexed8,但由于每像素值的采样,此参数应为(不存在的)QImage::Format_Indexed16,这导致内存损坏。该补丁回退到读取 tiff 图像的“普通”方式。

注意:Tenable Network Security 已直接从 DLA 安全公告中提取上述描述块。Tenable 已尝试在不引入其他问题的情况下尽可能进行了自动整理和排版。

解决方案

升级受影响的程序包。

另见

https://lists.debian.org/debian-lts-announce/2014/12/msg00019.html

https://packages.debian.org/source/squeeze-lts/qt4-x11

插件详情

严重性: High

ID: 82100

文件名: debian_DLA-117.nasl

版本: 1.4

类型: local

代理: unix

发布时间: 2015/3/26

最近更新时间: 2021/1/11

支持的传感器: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

风险信息

VPR

风险因素: Medium

分数: 5.9

CVSS v2

风险因素: High

基本分数: 9.3

时间分数: 8.1

矢量: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

漏洞信息

CPE: p-cpe:/a:debian:debian_linux:libqt4-sql-mysql, p-cpe:/a:debian:debian_linux:libqt4-webkit, p-cpe:/a:debian:debian_linux:libqt4-xml, p-cpe:/a:debian:debian_linux:qt4-qmake, p-cpe:/a:debian:debian_linux:libqt4-sql-tds, p-cpe:/a:debian:debian_linux:qt4-demos-dbg, p-cpe:/a:debian:debian_linux:libqt4-sql, p-cpe:/a:debian:debian_linux:libqt4-sql-ibase, p-cpe:/a:debian:debian_linux:libqtcore4, p-cpe:/a:debian:debian_linux:libqt4-assistant, p-cpe:/a:debian:debian_linux:libqt4-help, p-cpe:/a:debian:debian_linux:libqt4-sql-psql, p-cpe:/a:debian:debian_linux:libqt4-core, p-cpe:/a:debian:debian_linux:libqt4-sql-sqlite2, p-cpe:/a:debian:debian_linux:libqt4-svg, p-cpe:/a:debian:debian_linux:qt4-qtconfig, p-cpe:/a:debian:debian_linux:libqt4-opengl-dev, p-cpe:/a:debian:debian_linux:libqt4-sql-odbc, p-cpe:/a:debian:debian_linux:qt4-demos, p-cpe:/a:debian:debian_linux:libqt4-phonon, p-cpe:/a:debian:debian_linux:qt4-designer, p-cpe:/a:debian:debian_linux:qt4-dev-tools, p-cpe:/a:debian:debian_linux:libqt4-scripttools, p-cpe:/a:debian:debian_linux:libqtgui4, cpe:/o:debian:debian_linux:6.0, p-cpe:/a:debian:debian_linux:libqt4-webkit-dbg, p-cpe:/a:debian:debian_linux:libqt4-dbus, p-cpe:/a:debian:debian_linux:libqt4-dev, p-cpe:/a:debian:debian_linux:libqt4-qt3support, p-cpe:/a:debian:debian_linux:libqt4-gui, p-cpe:/a:debian:debian_linux:libqt4-designer, p-cpe:/a:debian:debian_linux:libqt4-xmlpatterns-dbg, p-cpe:/a:debian:debian_linux:qt4-doc, p-cpe:/a:debian:debian_linux:libqt4-multimedia, p-cpe:/a:debian:debian_linux:libqt4-test, p-cpe:/a:debian:debian_linux:libqt4-network, p-cpe:/a:debian:debian_linux:qt4-doc-html, p-cpe:/a:debian:debian_linux:libqt4-script, p-cpe:/a:debian:debian_linux:libqt4-sql-sqlite, p-cpe:/a:debian:debian_linux:libqt4-opengl, p-cpe:/a:debian:debian_linux:libqt4-xmlpatterns, p-cpe:/a:debian:debian_linux:libqt4-dbg

必需的 KB 项: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

易利用性: No known exploits are available

补丁发布日期: 2014/12/21

参考资料信息

CVE: CVE-2011-3193, CVE-2011-3194

BID: 49723, 49724