Full Disclosure mailing list archives
[OVSA20121112] OpenVAS Manager Vulnerable To Command Injection
From: Tim Brown <timb () openvas org>
Date: Tue, 13 Nov 2012 15:09:33 +0000
Summary It has been identified that OpenVAS Manager is vulnerable to command injection due to insufficient validation of user supplied data when processing OMP requests. It has been identified that this vulnerability may allow arbitrary code to be executed with the privileges of the OpenVAS Manager on vulnerable systems. CVE-2012-5520 has been assigned to this vulnerability. Current Status As of the 20th January 2011, the state of the vulnerabilities is believed to be as follows. A patch has been supplied by Greenbone Networks which it successfully resolves this vulnerability. New releases of both 3.0.x and 4.0.x have also been created which incorporate this patch. Thanks OpenVAS would like to thank Andre Heinecke of Greenbone Networks for his help in reporting the vulnerability. -- Tim Brown <mailto:timb@openvas,org> <http://www.openvas.org/>
Attachment:
OVSA20121112.txt
Description:
Attachment:
signature.asc
Description: This is a digitally signed message part.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- [OVSA20121112] OpenVAS Manager Vulnerable To Command Injection Tim Brown (Nov 14)
- Re: [OVSA20121112] OpenVAS Manager Vulnerable To Command Injection Tim Brown (Nov 14)
- Re: [oss-security] Re: [OVSA20121112] OpenVAS Manager Vulnerable To Command Injection Jan Lieskovsky (Nov 14)
- Re: [oss-security] Re: [OVSA20121112] OpenVAS Manager Vulnerable To Command Injection Michal Ambroz (Nov 14)
- Re: [oss-security] Re: [OVSA20121112] OpenVAS Manager Vulnerable To Command Injection Jan Lieskovsky (Nov 14)
- Re: [OVSA20121112] OpenVAS Manager Vulnerable To Command Injection Tim Brown (Nov 14)