Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2006:142: heartbeat Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the heartbeat package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2006:142 (heartbeat).
Two vulnerabilities in heartbeat prior to 2.0.6 was discovered by Yan
Rong Ge. The first is that heartbeat would set insecure permissions in
an shmget call for shared memory, allowing a local attacker to cause an
unspecified denial of service via unknown vectors (CVE-2006-3815).
The second is a remote vulnerability that could allow allow the master
control process to read invalid memory due to a specially crafted
heartbeat message and die of a SEGV, all prior to any authentication
Updated packages have been patched to correct these issues.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:142
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.