OracleVM 3.3 : rsyslog (OVMSA-2014-0030)

high Nessus Plugin ID 79545

Synopsis

The remote OracleVM host is missing a security update.

Description

The remote OracleVM system is missing necessary patches to address critical security updates :

- use setsid to get a controlling session and process group [Orabug: 17346261] (Todd Vierling)

- fix (CVE-2014-3634) resolves: #1149148

- drop patch 5 which introduced a regression resolves:
#927405 reverts: #847568

- add a patch to prevent 'RepeatedMsgReduction' causing missing hostnames resolves: #893197

- add a patch to enable specifying UID/GID as a number resolves: #886117

- add a patch to prevent a segfault in gssapi resolves:
#862517

Solution

Update the affected rsyslog package.

See Also

http://www.nessus.org/u?033bcde4

Plugin Details

Severity: High

ID: 79545

File Name: oraclevm_OVMSA-2014-0030.nasl

Version: 1.8

Type: local

Published: 11/26/2014

Updated: 1/4/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:oracle:vm_server:3.3, p-cpe:/a:oracle:vm:rsyslog

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 11/4/2014

Vulnerability Publication Date: 11/1/2014

Reference Information

CVE: CVE-2014-3634

BID: 70187