Fedora 14 : libHX-3.6-1.fc14 / pam_mount-2.5-1.fc14 (2010-12950)

critical Nessus Plugin ID 50389

Language:

Synopsis

The remote Fedora host is missing one or more security updates.

Description

Update to libHX 3.6 fixing a buffer overflow in HX_split() :

- http://libhx.git.sourceforge.net/git/gitweb.cgi?p=libhx/ libhx;a=commitdiff;h=904a46f90d

pam_mount v2.5 (August 10 2010) =============================== Changes :

- mount.crypt: fix incorrect processing of binary files in keyfile passthrough

- call mount.crypt by means of mount -t crypt (selinux), same for umount

- reorder the default path to search in /usr/local first, then /usr, /

- config: add missing fd0ssh command to restore volumes using ssh

- ofl is now run as a separate process (selinux policy simplification)

libHX v3.6 (August 16 2010) =========================== Fixed :

- bitmap: set/clear/test had no effect due to wrong type selection

- bitmap: avoid left-shift larger than type on 64-bit

- string: fixed buffer overflow in HX_split when too few fields were present in the input

libHX 3.5 (August 01 2010) ========================== Fixed :

- format2: failure to skip escaped char in '%(echo foo\ bar)' was corrected

- proc: properly check for HXPROC_STDx--HXPROC_STDx_NULL overlap

- strquote: do not cause allocation with invalid format numbers Enhancements :

- format2: add the %(exec) function

- format2: add the %(shell) function

- format2: security feature for %(exec) and %(shell)

- format2: add the %(snl) function

- string: HX_strquote gained HXQUOTE_LDAPFLT (LDAP search filter) support

- string: HX_strquote gained HXQUOTE_LDAPRDN (LDAP relative DN) support Changes :

- format1: removed older formatter in favor of format2

- format2: add check for empty key

- format2: function-specific delimiters

- format2: do nest-counting even with normal parentheses

- format2: check for zero-argument function calls

- hashmap: do not needlessy change TID when no reshape was done

- string: HX_basename (the fast variant) now recognizes the root directory

- string: HX_basename now returns the trailing component with slashes instead of everything after the last slash (which may have been nothing)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected libHX and / or pam_mount packages.

See Also

http://www.nessus.org/u?6bfbed59

https://bugzilla.redhat.com/show_bug.cgi?id=625866

http://www.nessus.org/u?35fb2b43

http://www.nessus.org/u?f4b7ea31

Plugin Details

Severity: Critical

ID: 50389

File Name: fedora_2010-12950.nasl

Version: 1.11

Type: local

Agent: unix

Published: 10/29/2010

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:14, p-cpe:/a:fedoraproject:fedora:libhx, p-cpe:/a:fedoraproject:fedora:pam_mount

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/17/2010

Reference Information

CVE: CVE-2010-2947

BID: 42592

FEDORA: 2010-12950