lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-Id: <201211201348.qAKDmHFd021465@sf01web2.securityfocus.com> Date: Tue, 20 Nov 2012 13:48:17 GMT From: roman.fiedler@....ac.at To: bugtraq@...urityfocus.com Subject: OSSIM 4.0.2 open-source SIEM solution does not verify .deb signatures It seems that OSSIM does not check the signature when running apt updates via network. This would allow MITM attackers to install arbitrary code when updating OSSIM. The issue seems to be already known for some time although there is no confirmation from the company AlienVault behind it. So it might be, that only the non-commercial version is affected. See http://forums.alienvault.com/discussion/512/looking-for-confirmation-of-security-issue-mitm-might-execute-arbitrary-code-on-ossim-during-update