Vulnerability Solutions

The Nimsoft Cloud Monitor Periodic Vulnerability Scan checks for the vulnerability below. To see the most recently added vulnerability solutions that are scanned by WatchMouse, go to the Vulnerability Solutions overview

Category: Mandriva Local Security Checks Risk factor: Medium Added: 31 Jan 2012
Synopsis:

The remote Mandriva host is missing one or more security-related
patches.

Description:

A vulnerability has been found and corrected in openssl:

OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which allows remote attackers to cause a denial of service via unspecified vectors. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4108 (CVE-2012-0050).

The updated packages have been patched to correct this issue.

The openssl0.9.8 packages for 2010.2 have been upgraded to the 0.9.8t version which is not vulnerable to this issue.

See also:

http://www.mandriva.com/security/advisories?name=MDVSA-2012:011

Solution:

Update the affected package(s).

Risk factor:

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)