lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <201101251145.34986.timb@openvas.org>
Date: Tue, 25 Jan 2011 11:45:18 +0000
From: Tim Brown <timb@...nvas.org>
To: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: [OVSA20110118] OpenVAS Manager Vulnerable To
	Command Injection

Summary

It has been identified that OpenVAS Manager is vulnerable to command injection 
due to insufficient validation of user supplied data when processing OMP 
requests. It has been identified that this vulnerability allows privilege 
escalation within the OpenVAS Manager but more complex injection may allow 
arbitrary code to be executed with the privileges of the OpenVAS Manager on 
vulnerable systems. CVE-2011-0018 has been assigned to this vulnerability.

The vulnerable code path is only accessible to authenticated users of OpenVAS 
Manager however it may also be triggered either directly or by using a cross-
site request forgery based attack via the Greenbone Security Assistant web 
application.

Current Status

As of the 20th January 2011, the state of the vulnerabilities is believed to 
be as follows. A patch has been supplied by Greenbone Networks which it 
successfully resolves this vulnerability. New releases of both 1.0.x and 2.0.x 
have also been created which incorporate this patch. Note that the cross-site 
address forgery elements of this vulnerability have not yet been addressed in 
the Greenbone Security Assistant web application.

Thanks

OpenVAS would like to thank Ronald Kingma and Alexander van Eee of ISSX for 
their help in reporting the vulnerability.
-- 
Tim Brown
<mailto:timb@...nvas.org>
<http://www.openvas.org/>

View attachment "OVSA20110118.txt" of type "text/plain" (4934 bytes)

Download attachment "signature.asc " of type "application/pgp-signature" (837 bytes)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ