RHEL 7 : CloudForms 4.6.6 (RHSA-2018:3816)

high Nessus Plugin ID 194110

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2018:3816 advisory.

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

* postgresql: Certain host connection parameters defeat client-side security defenses (CVE-2018-10915)

* postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements (CVE-2018-10925)

* postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask (CVE-2018-1053)

* postgresql: Uncontrolled search path element in pg_dump and other client applications (CVE-2018-1058)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Red Hat would like to thank the PostgreSQL project for reporting CVE-2018-10915, CVE-2018-10925 and CVE-2018-1053. Upstream acknowledges Andrew Krasichkov as the original reporter of CVE-2018-10915; and Tom Lane as the original reporter of CVE-2018-1053.

Additional Changes:

This update fixes various bugs and adds enhancements. Documentation for these changes is available from the Release Notes document.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/security/updates/classification/#important

http://www.nessus.org/u?168f64fc

https://bugzilla.redhat.com/show_bug.cgi?id=1539619

https://bugzilla.redhat.com/show_bug.cgi?id=1547044

https://bugzilla.redhat.com/show_bug.cgi?id=1609891

https://bugzilla.redhat.com/show_bug.cgi?id=1610547

https://bugzilla.redhat.com/show_bug.cgi?id=1612619

https://bugzilla.redhat.com/show_bug.cgi?id=1618836

https://bugzilla.redhat.com/show_bug.cgi?id=1623562

https://bugzilla.redhat.com/show_bug.cgi?id=1634809

https://bugzilla.redhat.com/show_bug.cgi?id=1635034

https://bugzilla.redhat.com/show_bug.cgi?id=1635255

https://bugzilla.redhat.com/show_bug.cgi?id=1635759

https://bugzilla.redhat.com/show_bug.cgi?id=1635788

https://bugzilla.redhat.com/show_bug.cgi?id=1638501

https://bugzilla.redhat.com/show_bug.cgi?id=1639351

https://bugzilla.redhat.com/show_bug.cgi?id=1639353

https://bugzilla.redhat.com/show_bug.cgi?id=1639364

https://bugzilla.redhat.com/show_bug.cgi?id=1640194

https://bugzilla.redhat.com/show_bug.cgi?id=1640258

https://bugzilla.redhat.com/show_bug.cgi?id=1640629

https://bugzilla.redhat.com/show_bug.cgi?id=1640631

https://bugzilla.redhat.com/show_bug.cgi?id=1641771

https://bugzilla.redhat.com/show_bug.cgi?id=1643042

https://bugzilla.redhat.com/show_bug.cgi?id=1643261

https://bugzilla.redhat.com/show_bug.cgi?id=1643263

https://bugzilla.redhat.com/show_bug.cgi?id=1643539

https://bugzilla.redhat.com/show_bug.cgi?id=1643959

https://bugzilla.redhat.com/show_bug.cgi?id=1644410

https://bugzilla.redhat.com/show_bug.cgi?id=1645198

https://bugzilla.redhat.com/show_bug.cgi?id=1645204

https://bugzilla.redhat.com/show_bug.cgi?id=1646435

https://bugzilla.redhat.com/show_bug.cgi?id=1646561

https://bugzilla.redhat.com/show_bug.cgi?id=1646564

https://bugzilla.redhat.com/show_bug.cgi?id=1646571

https://bugzilla.redhat.com/show_bug.cgi?id=1646599

https://bugzilla.redhat.com/show_bug.cgi?id=1646604

https://bugzilla.redhat.com/show_bug.cgi?id=1646605

https://bugzilla.redhat.com/show_bug.cgi?id=1646606

https://bugzilla.redhat.com/show_bug.cgi?id=1646613

https://bugzilla.redhat.com/show_bug.cgi?id=1646629

https://bugzilla.redhat.com/show_bug.cgi?id=1646646

https://bugzilla.redhat.com/show_bug.cgi?id=1647056

https://bugzilla.redhat.com/show_bug.cgi?id=1647108

https://bugzilla.redhat.com/show_bug.cgi?id=1647188

https://bugzilla.redhat.com/show_bug.cgi?id=1647489

https://bugzilla.redhat.com/show_bug.cgi?id=1648674

https://bugzilla.redhat.com/show_bug.cgi?id=1648948

https://bugzilla.redhat.com/show_bug.cgi?id=1648955

https://bugzilla.redhat.com/show_bug.cgi?id=1648991

https://bugzilla.redhat.com/show_bug.cgi?id=1649033

https://bugzilla.redhat.com/show_bug.cgi?id=1649380

https://bugzilla.redhat.com/show_bug.cgi?id=1649419

https://bugzilla.redhat.com/show_bug.cgi?id=1650691

https://bugzilla.redhat.com/show_bug.cgi?id=1651291

https://bugzilla.redhat.com/show_bug.cgi?id=1651347

https://bugzilla.redhat.com/show_bug.cgi?id=1651391

https://bugzilla.redhat.com/show_bug.cgi?id=1653417

https://bugzilla.redhat.com/show_bug.cgi?id=1653710

https://bugzilla.redhat.com/show_bug.cgi?id=1654436

https://bugzilla.redhat.com/show_bug.cgi?id=1654463

https://bugzilla.redhat.com/show_bug.cgi?id=1655081

https://bugzilla.redhat.com/show_bug.cgi?id=1655143

https://bugzilla.redhat.com/show_bug.cgi?id=1655773

https://bugzilla.redhat.com/show_bug.cgi?id=1656168

https://bugzilla.redhat.com/show_bug.cgi?id=1656169

http://www.nessus.org/u?3b77e6a7

https://access.redhat.com/errata/RHSA-2018:3816

Plugin Details

Severity: High

ID: 194110

File Name: redhat-RHSA-2018-3816.nasl

Version: 1.1

Type: local

Agent: unix

Published: 4/27/2024

Updated: 6/3/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2018-1058

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:cfme-appliance-common, p-cpe:/a:redhat:enterprise_linux:postgresql96-docs, p-cpe:/a:redhat:enterprise_linux:postgresql96-libs, p-cpe:/a:redhat:enterprise_linux:cfme-gemset, p-cpe:/a:redhat:enterprise_linux:postgresql96-devel, p-cpe:/a:redhat:enterprise_linux:postgresql96-contrib, p-cpe:/a:redhat:enterprise_linux:postgresql96-plperl, p-cpe:/a:redhat:enterprise_linux:dbus-api-service, p-cpe:/a:redhat:enterprise_linux:postgresql96-plpython, p-cpe:/a:redhat:enterprise_linux:cfme, p-cpe:/a:redhat:enterprise_linux:cfme-appliance-tools, p-cpe:/a:redhat:enterprise_linux:cfme-amazon-smartstate, p-cpe:/a:redhat:enterprise_linux:httpd-configmap-generator, p-cpe:/a:redhat:enterprise_linux:postgresql96-pltcl, p-cpe:/a:redhat:enterprise_linux:postgresql96-test, p-cpe:/a:redhat:enterprise_linux:cfme-appliance, cpe:/o:redhat:enterprise_linux:7, p-cpe:/a:redhat:enterprise_linux:postgresql96-server, p-cpe:/a:redhat:enterprise_linux:postgresql96

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 12/13/2018

Vulnerability Publication Date: 2/8/2018

Reference Information

CVE: CVE-2018-1053, CVE-2018-1058, CVE-2018-10915, CVE-2018-10925

CWE: 20, 377, 863, 89

RHSA: 2018:3816