<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://www.nessus.org/">
<title>Nessus.org Plugins</title>
<link>http://www.nessus.org/scripts.php</link>
<description>All the newest security checks for the Nessus scanner</description>

<items>
<rdf:Seq>
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66915" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66914" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66913" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66912" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66911" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66910" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66909" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66908" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66907" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66906" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66905" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66904" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66903" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66902" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66901" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66900" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66899" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66898" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66897" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=66896" />
</rdf:Seq>
</items>
</channel>

<image rdf:about="http://www.nessus.org/images/RssLogo.jpg">
<title>Nessus Plugins</title>
<url>http://www.nessus.org/images/RssLogo.jpg</url>
<link>http://www.nessus.org/</link>
</image>

<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66915">
<title>Novell ZENworks Configuration Console Login.jsp language Parameter XSS</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote web server hosts a script that is affected by a cross-site<br />
scripting vulnerability.<br />
<br />
Description :<br />
<br />
The remote web server hosts a version of the ZENworks Configuration<br />
Console that is affected by a cross-site scripting vulnerability.  The<br />
'language' parameter is not properly validated in 'Login.jsp' and can be<br />
tampered with to inject arbitrary script code in a user's browser via a<br />
specially crafted POST request. <br />
<br />
Note that hosts that are affected by this issue are also likely to be<br />
affected by other vulnerabilities.<br />
<br />
See also :<br />
<br />
<a href="http://www.novell.com/support/kb/doc.php?id=7012025" target="_blank">http://www.novell.com/support/kb/doc.php?id=7012025</a><br />
<a href="http://www.novell.com/support/kb/doc.php?id=7012501" target="_blank">http://www.novell.com/support/kb/doc.php?id=7012501</a><br />
<br />
Solution :<br />
<br />
Upgrade to 11.2.3a Monthly Update 1 or later.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 4.3<br />
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)<br />
CVSS Temporal Score : 3.6<br />
(CVSS2#E:F/RL:OF/RC:C)<br />
Public Exploit Available : true<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66915</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66914">
<title>Novell ZENworks Control Center File Upload Remote Code Execution (intrusive check)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote host is affected by a remote code execution vulnerability.<br />
<br />
Description :<br />
<br />
The installed version of Novell ZENworks Control Center has a flaw with<br />
authentication checking on '/zenworks/jsp/index.jsp' that can allow a<br />
remote, unauthenticated attacker to upload arbitrary files and execute<br />
them with SYSTEM privileges.  Nessus has exploited this vulnerability to<br />
upload a file to the '/zenworks/css' directory.<br />
<br />
See also :<br />
<br />
<a href="http://www.novell.com/support/kb/doc.php?id=7011812" target="_blank">http://www.novell.com/support/kb/doc.php?id=7011812</a><br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-13-049/" target="_blank">http://www.zerodayinitiative.com/advisories/ZDI-13-049/</a><br />
<br />
Solution :<br />
<br />
Upgrade to ZENworks 11.2.2 and apply the interim fix, or apply 11.2.3a<br />
Monthly Update 1 for 11.2.3 installs.<br />
<br />
Risk factor :<br />
<br />
Critical / CVSS Base Score : 10.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)<br />
CVSS Temporal Score : 8.3<br />
(CVSS2#E:F/RL:OF/RC:C)<br />
Public Exploit Available : true<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66914</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66913">
<title>Novell ZENworks Configuration Management &lt; 11.2.3a Monthly Update 1 Multiple Vulnerabilities (credentialed check)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote host has an application that is affected by multiple<br />
vulnerabilities.<br />
<br />
Description :<br />
<br />
The remote host has a version of Novell ZENworks Configuration<br />
Management installed prior to 11.2.3a Monthly Update 1.  It is,<br />
therefore, affected by the following vulnerabilities:<br />
<br />
  - An open redirect vulnerability exists on the ZENworks<br />
    Control Center login page due to improper validation of<br />
    the 'fwdToURL' parameter. (CVE-2013-1093)<br />
<br />
  - The ZENworks Control Center Login.jsp script is affected<br />
    by a cross-site scripting vulnerability that exists due<br />
    to improper validation on the 'language' parameter.<br />
    (CVE-2013-1094)<br />
<br />
  - A cross-site scripting vulnerability exists due to<br />
    improper validation of input when handling 'onError'<br />
    events. (CVE-2013-1095)<br />
<br />
  - A cross-site scripting vulnerability exists due to<br />
    improper validation of input when handling frame tag<br />
    'onload' events. (CVE-2013-1097)<br />
<br />
See also :<br />
<br />
<a href="http://www.novell.com/support/kb/doc.php?id=7012025" target="_blank">http://www.novell.com/support/kb/doc.php?id=7012025</a><br />
<a href="http://www.novell.com/support/kb/doc.php?id=7012499" target="_blank">http://www.novell.com/support/kb/doc.php?id=7012499</a><br />
<a href="http://www.novell.com/support/kb/doc.php?id=7012501" target="_blank">http://www.novell.com/support/kb/doc.php?id=7012501</a><br />
<a href="http://www.novell.com/support/kb/doc.php?id=7012500" target="_blank">http://www.novell.com/support/kb/doc.php?id=7012500</a><br />
<a href="http://www.novell.com/support/kb/doc.php?id=7012502" target="_blank">http://www.novell.com/support/kb/doc.php?id=7012502</a><br />
<br />
Solution :<br />
<br />
Upgrade to Novell ZENworks 11.2.3a Monthly Update 1 or later.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 4.3<br />
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)<br />
CVSS Temporal Score : 3.6<br />
(CVSS2#E:F/RL:OF/RC:C)<br />
Public Exploit Available : true<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66913</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66912">
<title>SuSE 11.2 Security Update : Linux kernel (SAT Patch Numbers 7811 / 7813 / 7814)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE 11 host is missing one or more security updates.<br />
<br />
Description :<br />
<br />
The SUSE Linux Enterprise 11 Service Pack 2 kernel has been updated to<br />
Linux kernel 3.0.80 which fixes various bugs and security issues.<br />
<br />
The following security issues have been fixed :<br />
<br />
  - Timing side channel on attacks were possible on<br />
    /dev/ptmx that could allow local attackers to predict<br />
    keypresses like e.g. passwords. This has been fixed<br />
    again by updating accessed/modified time on the pty<br />
    devices in resolution of 8 seconds, so that idle time<br />
    detection can still work. (CVE-2013-0160)<br />
<br />
  - The vcc_recvmsg function in net/atm/common.c in the<br />
    Linux kernel did not initialize a certain length<br />
    variable, which allowed local users to obtain sensitive<br />
    information from kernel stack memory via a crafted<br />
    recvmsg or recvfrom system call. (CVE-2013-3222)<br />
<br />
  - The ax25_recvmsg function in net/ax25/af_ax25.c in the<br />
    Linux kernel did not initialize a certain data<br />
    structure, which allowed local users to obtain sensitive<br />
    information from kernel stack memory via a crafted<br />
    recvmsg or recvfrom system call. (CVE-2013-3223)<br />
<br />
  - The bt_sock_recvmsg function in<br />
    net/bluetooth/af_bluetooth.c in the Linux kernel did not<br />
    properly initialize a certain length variable, which<br />
    allowed local users to obtain sensitive information from<br />
    kernel stack memory via a crafted recvmsg or recvfrom<br />
    system call. (CVE-2013-3224)<br />
<br />
  - The rfcomm_sock_recvmsg function in<br />
    net/bluetooth/rfcomm/sock.c in the Linux kernel did not<br />
    initialize a certain length variable, which allowed<br />
    local users to obtain sensitive information from kernel<br />
    stack memory via a crafted recvmsg or recvfrom system<br />
    call. (CVE-2013-3225)<br />
<br />
  - The caif_seqpkt_recvmsg function in<br />
    net/caif/caif_socket.c in the Linux kernel did not<br />
    initialize a certain length variable, which allowed<br />
    local users to obtain sensitive information from kernel<br />
    stack memory via a crafted recvmsg or recvfrom system<br />
    call. (CVE-2013-3227)<br />
<br />
  - The irda_recvmsg_dgram function in net/irda/af_irda.c in<br />
    the Linux kernel did not initialize a certain length<br />
    variable, which allowed local users to obtain sensitive<br />
    information from kernel stack memory via a crafted<br />
    recvmsg or recvfrom system call. (CVE-2013-3228)<br />
<br />
  - The iucv_sock_recvmsg function in net/iucv/af_iucv.c in<br />
    the Linux kernel did not initialize a certain length<br />
    variable, which allowed local users to obtain sensitive<br />
    information from kernel stack memory via a crafted<br />
    recvmsg or recvfrom system call. (CVE-2013-3229)<br />
<br />
  - The llc_ui_recvmsg function in net/llc/af_llc.c in the<br />
    Linux kernel did not initialize a certain length<br />
    variable, which allowed local users to obtain sensitive<br />
    information from kernel stack memory via a crafted<br />
    recvmsg or recvfrom system call. (CVE-2013-3231)<br />
<br />
  - The nr_recvmsg function in net/netrom/af_netrom.c in the<br />
    Linux kernel did not initialize a certain data<br />
    structure, which allowed local users to obtain sensitive<br />
    information from kernel stack memory via a crafted<br />
    recvmsg or recvfrom system call. (CVE-2013-3232)<br />
<br />
  - The rose_recvmsg function in net/rose/af_rose.c in the<br />
    Linux kernel did not initialize a certain data<br />
    structure, which allowed local users to obtain sensitive<br />
    information from kernel stack memory via a crafted<br />
    recvmsg or recvfrom system call. (CVE-2013-3234)<br />
<br />
  - net/tipc/socket.c in the Linux kernel did not initialize<br />
    a certain data structure and a certain length variable,<br />
    which allowed local users to obtain sensitive<br />
    information from kernel stack memory via a crafted<br />
    recvmsg or recvfrom system call. (CVE-2013-3235)<br />
<br />
  - The crypto API in the Linux kernel did not initialize<br />
    certain length variables, which allowed local users to<br />
    obtain sensitive information from kernel stack memory<br />
    via a crafted recvmsg or recvfrom system call, related<br />
    to the hash_recvmsg function in crypto/algif_hash.c and<br />
    the skcipher_recvmsg function in<br />
    crypto/algif_skcipher.c. (CVE-2013-3076)<br />
<br />
  - The scm_set_cred function in include/net/scm.h in the<br />
    Linux kernel used incorrect uid and gid values during<br />
    credentials passing, which allowed local users to gain<br />
    privileges via a crafted application. (CVE-2013-1979)<br />
<br />
  - A kernel information leak via tkill/tgkill was fixed.<br />
    The following bugs have been fixed :<br />
<br />
  - reiserfs: fix spurious multiple-fill in<br />
    reiserfs_readdir_dentry. (bnc#822722)<br />
<br />
  - libfc: do not exch_done() on invalid sequence ptr.<br />
    (bnc#810722)<br />
<br />
  - netfilter: ip6t_LOG: fix logging of packet mark.<br />
    (bnc#821930)<br />
<br />
  - hyperv: use 3.4 as LIC version string. (bnc#822431)<br />
<br />
  - virtio_net: introduce VIRTIO_NET_HDR_F_DATA_VALID.<br />
    (bnc#819655)<br />
<br />
  - xen/netback: do not disconnect frontend when seeing<br />
    oversize packet.<br />
<br />
  - xen/netfront: reduce gso_max_size to account for max TCP<br />
    header.<br />
<br />
  - xen/netfront: fix kABI after 'reduce gso_max_size to<br />
    account for max TCP header'.<br />
<br />
  - xfs: Fix kABI due to change in xfs_buf. (bnc#815356)<br />
<br />
  - xfs: fix race while discarding buffers [V4] (bnc#815356<br />
    (comment 36)).<br />
<br />
  - xfs: Serialize file-extending direct IO. (bnc#818371)<br />
<br />
  - xhci: Do not switch webcams in some HP ProBooks to XHCI.<br />
    (bnc#805804)<br />
<br />
  - bluetooth: Do not switch BT on HP ProBook 4340.<br />
    (bnc#812281)<br />
<br />
  - s390/ftrace: fix mcount adjustment. (bnc#809895)<br />
<br />
  - mm: memory_dev_init make sure nmi watchdog does not<br />
    trigger while registering memory sections. (bnc#804609,<br />
    bnc#820434)<br />
<br />
  - patches.fixes/xfs-backward-alloc-fix.diff: xfs: Avoid<br />
    pathological backwards allocation. (bnc#805945)<br />
<br />
  - mm: compaction: Restart compaction from near where it<br />
    left off<br />
<br />
  - mm: compaction: cache if a pageblock was scanned and no<br />
    pages were isolated<br />
<br />
  - mm: compaction: clear PG_migrate_skip based on<br />
    compaction and reclaim activity<br />
<br />
  - mm: compaction: Scan PFN caching KABI workaround<br />
<br />
  - mm: page_allocator: Remove first_pass guard<br />
<br />
  - mm: vmscan: do not stall on writeback during memory<br />
    compaction Cache compaction restart points for faster<br />
    compaction cycles. (bnc#816451)<br />
<br />
  - qlge: fix dma map leak when the last chunk is not<br />
    allocated. (bnc#819519)<br />
<br />
  - SUNRPC: Get rid of the redundant xprt-&gt;shutdown bit<br />
    field. (bnc#800907)<br />
<br />
  - SUNRPC: Ensure that we grab the XPRT_LOCK before calling<br />
    xprt_alloc_slot. (bnc#800907)<br />
<br />
  - SUNRPC: Fix a UDP transport regression. (bnc#800907)<br />
<br />
  - SUNRPC: Allow caller of rpc_sleep_on() to select<br />
    priority levels. (bnc#800907)<br />
<br />
  - SUNRPC: Replace xprt-&gt;resend and xprt-&gt;sending with a<br />
    priority queue. (bnc#800907)<br />
<br />
  - SUNRPC: Fix potential races in xprt_lock_write_next().<br />
    (bnc#800907)<br />
<br />
  - md: cannot re-add disks after recovery. (bnc#808647)<br />
<br />
  - fs/xattr.c:getxattr(): improve handling of allocation<br />
    failures. (bnc#818053)<br />
<br />
  - fs/xattr.c:listxattr(): fall back to vmalloc() if<br />
    kmalloc() failed. (bnc#818053)<br />
<br />
  - fs/xattr.c:setxattr(): improve handling of allocation<br />
    failures. (bnc#818053)<br />
<br />
  - fs/xattr.c: suppress page allocation failure warnings<br />
    from sys_listxattr(). (bnc#818053)<br />
<br />
  - virtio-blk: Call revalidate_disk() upon online disk<br />
    resize. (bnc#817339)<br />
<br />
  - usb-storage: CY7C68300A chips do not support Cypress<br />
    ATACB. (bnc#819295)<br />
<br />
  - patches.kernel.org/patch-3.0.60-61: Update references<br />
    (add bnc#810580).<br />
<br />
  - usb: Using correct way to clear usb3.0 devices remote<br />
    wakeup feature. (bnc#818516)<br />
<br />
  - xhci: Fix TD size for isochronous URBs. (bnc#818514)<br />
<br />
  - ALSA: hda - fixup D3 pin and right channel mute on<br />
    Haswell HDMI audio. (bnc#818798)<br />
<br />
  - ALSA: hda - Apply pin-enablement workaround to all<br />
    Haswell HDMI codecs. (bnc#818798)<br />
<br />
  - xfs: fallback to vmalloc for large buffers in<br />
    xfs_attrmulti_attr_get. (bnc#818053)<br />
<br />
  - xfs: fallback to vmalloc for large buffers in<br />
    xfs_attrlist_by_handle. (bnc#818053)<br />
<br />
  - xfs: xfs: fallback to vmalloc for large buffers in<br />
    xfs_compat_attrlist_by_handle. (bnc#818053)<br />
<br />
  - xHCI: store rings type.<br />
<br />
  - xhci: Fix hang on back-to-back Set TR Deq Ptr commands.<br />
<br />
  - xHCI: check enqueue pointer advance into dequeue seg.<br />
<br />
  - xHCI: store rings last segment and segment numbers.<br />
<br />
  - xHCI: Allocate 2 segments for transfer ring.<br />
<br />
  - xHCI: count free TRBs on transfer ring.<br />
<br />
  - xHCI: factor out segments allocation and free function.<br />
<br />
  - xHCI: update sg tablesize.<br />
<br />
  - xHCI: set cycle state when allocate rings.<br />
<br />
  - xhci: Reserve one command for USB3 LPM disable.<br />
<br />
  - xHCI: dynamic ring expansion.<br />
<br />
  - xhci: Do not warn on empty ring for suspended devices.<br />
<br />
  - md/raid1: Do not release reference to device while<br />
    handling read error. (bnc#809122, bnc#814719)<br />
<br />
  - rpm/mkspec: Stop generating the get_release_number.sh<br />
    file.<br />
<br />
  - rpm/kernel-spec-macros: Properly handle KOTD release<br />
    numbers with .g suffix.<br />
<br />
  - rpm/kernel-spec-macros: Drop the %release_num macro We<br />
    no longer put the -rcX tag into the release string.<br />
<br />
  - rpm/kernel-*.spec.in, rpm/mkspec: Do not force the<br />
    '&lt;RELEASE&gt;' string in specfiles.<br />
<br />
  - mm/mmap: check for RLIMIT_AS before unmapping.<br />
    (bnc#818327)<br />
<br />
  - mm: Fix add_page_wait_queue() to work for PG_Locked bit<br />
    waiters. (bnc#792584)<br />
<br />
  - mm: Fix add_page_wait_queue() to work for PG_Locked bit<br />
    waiters. (bnc#792584)<br />
<br />
  - bonding: only use primary address for ARP. (bnc#815444)<br />
<br />
  - bonding: remove entries for master_ip and vlan_ip and<br />
    query devices instead. (bnc#815444)<br />
<br />
  - mm: speedup in __early_pfn_to_nid. (bnc#810624)<br />
<br />
  - TTY: fix atime/mtime regression. (bnc#815745)<br />
<br />
  - sd_dif: problem with verify of type 1 protection<br />
    information (PI). (bnc#817010)<br />
<br />
  - sched: harden rq rt usage accounting. (bnc#769685,<br />
    bnc#788590)<br />
<br />
  - rcu: Avoid spurious RCU CPU stall warnings. (bnc#816586)<br />
<br />
  - rcu: Dump local stack if cannot dump all CPUs stacks.<br />
    (bnc#816586)<br />
<br />
  - rcu: Fix detection of abruptly-ending stall.<br />
    (bnc#816586)<br />
<br />
  - rcu: Suppress NMI backtraces when stall ends before<br />
    dump. (bnc#816586)<br />
<br />
  - Update Xen patches to 3.0.74.<br />
<br />
  - btrfs: do not re-enter when allocating a chunk.<br />
<br />
  - btrfs: save us a read_lock.<br />
<br />
  - btrfs: Check CAP_DAC_READ_SEARCH for<br />
    BTRFS_IOC_INO_PATHS.<br />
<br />
  - btrfs: remove unused fs_info from btrfs_decode_error().<br />
<br />
  - btrfs: handle null fs_info in btrfs_panic().<br />
<br />
  - btrfs: fix varargs in __btrfs_std_error.<br />
<br />
  - btrfs: fix the race between bio and btrfs_stop_workers.<br />
<br />
  - btrfs: fix NULL pointer after aborting a transaction.<br />
<br />
  - btrfs: fix infinite loop when we abort on mount.<br />
<br />
  - xfs: Do not allocate new buffers on every call to<br />
    _xfs_buf_find. (bnc#763968)<br />
<br />
  - xfs: fix buffer lookup race on allocation failure.<br />
    (bnc#763968)<br />
<br />
See also :<br />
<br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=763968" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=763968</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=764209" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=764209</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=768052" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=768052</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=769685" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=769685</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=788590" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=788590</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=792584" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=792584</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=793139" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=793139</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=797042" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=797042</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=797175" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=797175</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=800907" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=800907</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=802153" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=802153</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=804154" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=804154</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=804609" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=804609</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=805804" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=805804</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=805945" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=805945</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=806431" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=806431</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=806980" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=806980</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=808647" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=808647</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=809122" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=809122</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=809155" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=809155</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=809748" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=809748</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=809895" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=809895</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=810580" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=810580</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=810624" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=810624</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=810722" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=810722</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=812281" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=812281</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=814719" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=814719</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=815356" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=815356</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=815444" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=815444</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=815745" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=815745</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=816443" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=816443</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=816451" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=816451</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=816586" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=816586</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=816668" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=816668</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=816708" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=816708</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=817010" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=817010</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=817339" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=817339</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=818053" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=818053</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=818327" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=818327</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=818371" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=818371</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=818514" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=818514</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=818516" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=818516</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=818798" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=818798</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=819295" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=819295</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=819519" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=819519</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=819655" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=819655</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=819789" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=819789</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=820434" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=820434</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=821560" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=821560</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=821930" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=821930</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=822431" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=822431</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=822722" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=822722</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-0160.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-0160.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-1979.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-1979.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3076.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3076.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3222.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3222.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3223.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3223.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3224.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3224.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3225.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3225.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3227.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3227.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3228.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3228.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3229.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3229.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3231.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3231.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3232.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3232.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3234.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3234.html</a><br />
<a href="http://support.novell.com/security/cve/CVE-2013-3235.html" target="_blank">http://support.novell.com/security/cve/CVE-2013-3235.html</a><br />
<br />
Solution :<br />
<br />
Apply SAT patch number 7811 / 7813 / 7814 as appropriate.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 6.9<br />
(CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66912</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66911">
<title>Mandriva Linux Security Advisory : owncloud (MDVSA-2013:175)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Mandriva Linux host is missing a security update.<br />
<br />
Description :<br />
<br />
Multiple vulnerabilities has been found and corrected in owncloud :<br />
<br />
Cross-site scripting (XSS) vulnerabilities in js/viewer.js inside the<br />
files_videoviewer application via multiple unspecified vectors in all<br />
ownCloud versions prior to 5.0.7 and 4.5.12 allows authenticated<br />
remote attackers to inject arbitrary web script or HTML via shared<br />
files (CVE-2013-2150).<br />
<br />
Cross-site scripting (XSS) vulnerabilities in core/js/oc-dialogs.js<br />
via multiple unspecified vectors in all ownCloud versions prior to<br />
5.0.7 and other versions before 4.0.16 allows authenticated remote<br />
attackers to inject arbitrary web script or HTML via shared files<br />
(CVE-2013-2149).<br />
<br />
This advisory provides the latest versions of owncloud (5.0.7) which<br />
is not vulnerable to these issues.<br />
<br />
See also :<br />
<br />
<a href="http://owncloud.org/about/security/advisories/oC-SA-2013-028/" target="_blank">http://owncloud.org/about/security/advisories/oC-SA-2013-028/</a><br />
<br />
Solution :<br />
<br />
Update the affected owncloud package.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 4.3<br />
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)<br />
CVSS Temporal Score : 3.6<br />
(CVSS2#E:F/RL:OF/RC:C)<br />
Public Exploit Available : true<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66911</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66910">
<title>Debian DSA-2709-1 : wireshark - several vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Debian host is missing a security-related update.<br />
<br />
Description :<br />
<br />
Multiple vulnerabilities were discovered in the dissectors for CAPWAP,<br />
GMR-1 BCCH, PPP, NBAP, RDP, HTTP, DCP ETSI and in the Ixia IxVeriWave<br />
file parser, which could result in denial of service or the execution<br />
of arbitrary code.<br />
<br />
See also :<br />
<br />
<a href="http://www.debian.org/security/2013/dsa-2709" target="_blank">http://www.debian.org/security/2013/dsa-2709</a><br />
<br />
Solution :<br />
<br />
Upgrade the wireshark packages.<br />
<br />
For the stable distribution (wheezy), these problems have been fixed<br />
in version 1.8.2-5wheezy4.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 5.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66910</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66909">
<title>VMware vCenter Update Manager Multiple Vulnerabilities (VMSA-2012-0013)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote host has an update manager installed that is affected by<br />
multiple vulnerabilities.<br />
<br />
Description :<br />
<br />
The version of VMware vCenter Update Manager installed on the remote<br />
Windows host is 4.0 earlier than Update 4a, or 4.1 earlier than Update<br />
3.  Such versions use a version of the Oracle JRE 1.5 that is affected<br />
by multiple vulnerabilities.<br />
<br />
See also :<br />
<br />
<a href="http://www.vmware.com/security/advisories/VMSA-2012-0013.html" target="_blank">http://www.vmware.com/security/advisories/VMSA-2012-0013.html</a><br />
<a href="http://lists.vmware.com/pipermail/security-announce/2012/000197.html" target="_blank">http://lists.vmware.com/pipermail/security-announce/2012/000197.html</a><br />
<br />
Solution :<br />
<br />
Upgrade to vCenter Update Manager 4.0 Update 4a / 4.1 Update 3 or<br />
later.<br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 7.8<br />
(CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N)<br />
CVSS Temporal Score : 6.1<br />
(CVSS2#E:POC/RL:OF/RC:C)<br />
Public Exploit Available : true<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66909</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66908">
<title>VMware vCenter Update Manager Detection (credentialed)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
A patch management application is installed on the remote Windows<br />
host.<br />
<br />
Description :<br />
<br />
VMware vCenter Update Manager (also known as vSphere Update Manager)<br />
was detected on the remote Windows host.  This application is used to<br />
manage patches on vSphere hosts.<br />
<br />
See also :<br />
<br />
<a href="http://www.nessus.org/u?3cb29e7a" target="_blank">http://www.nessus.org/u?3cb29e7a</a><br />
<br />
Solution :<br />
<br />
n/a<br />
<br />
Risk factor :<br />
<br />
None<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66908</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66907">
<title>FreeBSD : tor -- guard discovery (80af2677-d6c0-11e2-8f5e-001966155bea)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote FreeBSD host is missing a security-related update.<br />
<br />
Description :<br />
<br />
The Tor Project reports :<br />
<br />
Disable middle relay queue overfill detection code due to possible<br />
guard discovery attack<br />
<br />
See also :<br />
<br />
<a href="https://trac.torproject.org/projects/tor/ticket/9072" target="_blank">https://trac.torproject.org/projects/tor/ticket/9072</a><br />
<a href="http://www.nessus.org/u?b10ce9f9" target="_blank">http://www.nessus.org/u?b10ce9f9</a><br />
<br />
Solution :<br />
<br />
Update the affected package.<br />
<br />
Risk factor :<br />
<br />
High<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66907</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66906">
<title>Debian DSA-2708-1 : fail2ban - denial of service</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Debian host is missing a security-related update.<br />
<br />
Description :<br />
<br />
Krzysztof Katowicz-Kowalewski discovered a vulnerability in Fail2ban,<br />
a log monitoring and system which can act on attack by preventing<br />
hosts to connect to specified services using the local firewall.<br />
<br />
When using Fail2ban to monitor Apache logs, improper input validation<br />
in log parsing could enable a remote attacker to trigger an IP ban on<br />
arbitrary addresses, thus causing a denial of service.<br />
<br />
See also :<br />
<br />
<a href="http://www.debian.org/security/2013/dsa-2708" target="_blank">http://www.debian.org/security/2013/dsa-2708</a><br />
<br />
Solution :<br />
<br />
Upgrade the fail2ban packages.<br />
<br />
For the oldstable distribution (squeeze), this problem has been fixed<br />
in version 0.8.4-3+squeeze2.<br />
<br />
For the stable distribution (wheezy), this problem has been fixed in<br />
version 0.8.6-3wheezy2.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 4.3<br />
(CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P)<br />
CVSS Temporal Score : 3.4<br />
(CVSS2#E:POC/RL:OF/RC:ND)<br />
Public Exploit Available : true<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66906</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66905">
<title>Debian DSA-2707-1 : dbus - denial of service</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Debian host is missing a security-related update.<br />
<br />
Description :<br />
<br />
Alexandru Cornea discovered a vulnerability in libdbus caused by an<br />
implementation bug in _dbus_printf_string_upper_bound(). This<br />
vulnerability can be exploited by a local user to crash system<br />
services that use libdbus, causing denial of service. Depending on the<br />
dbus services running, it could lead to complete system crash.<br />
<br />
The oldstable distribution (squeeze) is not affected by this problem.<br />
<br />
See also :<br />
<br />
<a href="http://www.debian.org/security/2013/dsa-2707" target="_blank">http://www.debian.org/security/2013/dsa-2707</a><br />
<br />
Solution :<br />
<br />
Upgrade the dbus packages.<br />
<br />
For the stable distribution (wheezy), this problem has been fixed in<br />
version 1.6.8-1+deb7u1.<br />
<br />
Risk factor :<br />
<br />
High<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66905</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66904">
<title>Ubuntu 12.10 : linux vulnerabilities (USN-1881-1)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Ubuntu host is missing one or more security-related patches.<br />
<br />
Description :<br />
<br />
An information leak was discovered in the Linux kernel when inotify is<br />
used to monitor the /dev/ptmx device. A local user could exploit this<br />
flaw to discover keystroke timing and potentially discover sensitive<br />
information like password length. (CVE-2013-0160)<br />
<br />
An information leak was discovered in the Linux kernel's tkill and<br />
tgkill system calls when used from compat processes. A local user<br />
could exploit this flaw to examine potentially sensitive kernel<br />
memory. (CVE-2013-2141)<br />
<br />
A flaw was discovered in the Linux kernel's perf events subsystem for<br />
Intel Sandy Bridge and Ivy Bridge processors. A local user could<br />
exploit this flaw to cause a denial of service (system crash).<br />
(CVE-2013-2146)<br />
<br />
An information leak was discovered in the Linux kernel's crypto API. A<br />
local user could exploit this flaw to examine potentially sensitive<br />
information from the kernel's stack memory. (CVE-2013-3076)<br />
<br />
An information leak was discovered in the Linux kernel's rcvmsg path<br />
for ATM (Asynchronous Transfer Mode). A local user could exploit this<br />
flaw to examine potentially sensitive information from the kernel's<br />
stack memory. (CVE-2013-3222)<br />
<br />
An information leak was discovered in the Linux kernel's recvmsg path<br />
for ax25 address family. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3223)<br />
<br />
An information leak was discovered in the Linux kernel's recvmsg path<br />
for the bluetooth address family. A local user could exploit this flaw<br />
to examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3224)<br />
<br />
An information leak was discovered in the Linux kernel's bluetooth<br />
rfcomm protocol support. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3225)<br />
<br />
An information leak was discovered in the Linux kernel's CAIF protocol<br />
implementation. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3227)<br />
<br />
An information leak was discovered in the Linux kernel's IRDA<br />
(infrared) support subsystem. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3228)<br />
<br />
An information leak was discovered in the Linux kernel's s390 - z/VM<br />
support. A local user could exploit this flaw to examine potentially<br />
sensitive information from the kernel's stack memory. (CVE-2013-3229)<br />
<br />
An information leak was discovered in the Linux kernel's l2tp (Layer<br />
Two Tunneling Protocol) implementation. A local user could exploit<br />
this flaw to examine potentially sensitive information from the<br />
kernel's stack memory. (CVE-2013-3230)<br />
<br />
An information leak was discovered in the Linux kernel's llc (Logical<br />
Link Layer 2) support. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3231)<br />
<br />
An information leak was discovered in the Linux kernel's receive<br />
message handling for the netrom address family. A local user could<br />
exploit this flaw to obtain sensitive information from the kernel's<br />
stack memory. (CVE-2013-3232)<br />
<br />
An information leak was discovered in the Linux kernel's nfc (near<br />
field communication) support. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3233)<br />
<br />
An information leak was discovered in the Linux kernel's Rose X.25<br />
protocol layer. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3234)<br />
<br />
An information leak was discovered in the Linux kernel's TIPC<br />
(Transparent Inter Process Communication) protocol implementation. A<br />
local user could exploit this flaw to examine potentially sensitive<br />
information from the kernel's stack memory. (CVE-2013-3235).<br />
<br />
Solution :<br />
<br />
Update the affected linux-image-3.5.0-34-generic and / or<br />
linux-image-3.5.0-34-highbank packages.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 4.9<br />
(CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N)<br />
CVSS Temporal Score : 3.6<br />
(CVSS2#E:U/RL:OF/RC:C)<br />
Public Exploit Available : false<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66904</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66903">
<title>Ubuntu 12.04 LTS : linux-lts-quantal vulnerabilities (USN-1880-1)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Ubuntu host is missing a security-related patch.<br />
<br />
Description :<br />
<br />
An information leak was discovered in the Linux kernel when inotify is<br />
used to monitor the /dev/ptmx device. A local user could exploit this<br />
flaw to discover keystroke timing and potentially discover sensitive<br />
information like password length. (CVE-2013-0160)<br />
<br />
An information leak was discovered in the Linux kernel's tkill and<br />
tgkill system calls when used from compat processes. A local user<br />
could exploit this flaw to examine potentially sensitive kernel<br />
memory. (CVE-2013-2141)<br />
<br />
A flaw was discovered in the Linux kernel's perf events subsystem for<br />
Intel Sandy Bridge and Ivy Bridge processors. A local user could<br />
exploit this flaw to cause a denial of service (system crash).<br />
(CVE-2013-2146)<br />
<br />
An information leak was discovered in the Linux kernel's crypto API. A<br />
local user could exploit this flaw to examine potentially sensitive<br />
information from the kernel's stack memory. (CVE-2013-3076)<br />
<br />
An information leak was discovered in the Linux kernel's rcvmsg path<br />
for ATM (Asynchronous Transfer Mode). A local user could exploit this<br />
flaw to examine potentially sensitive information from the kernel's<br />
stack memory. (CVE-2013-3222)<br />
<br />
An information leak was discovered in the Linux kernel's recvmsg path<br />
for ax25 address family. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3223)<br />
<br />
An information leak was discovered in the Linux kernel's recvmsg path<br />
for the bluetooth address family. A local user could exploit this flaw<br />
to examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3224)<br />
<br />
An information leak was discovered in the Linux kernel's bluetooth<br />
rfcomm protocol support. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3225)<br />
<br />
An information leak was discovered in the Linux kernel's CAIF protocol<br />
implementation. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3227)<br />
<br />
An information leak was discovered in the Linux kernel's IRDA<br />
(infrared) support subsystem. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3228)<br />
<br />
An information leak was discovered in the Linux kernel's s390 - z/VM<br />
support. A local user could exploit this flaw to examine potentially<br />
sensitive information from the kernel's stack memory. (CVE-2013-3229)<br />
<br />
An information leak was discovered in the Linux kernel's l2tp (Layer<br />
Two Tunneling Protocol) implementation. A local user could exploit<br />
this flaw to examine potentially sensitive information from the<br />
kernel's stack memory. (CVE-2013-3230)<br />
<br />
An information leak was discovered in the Linux kernel's llc (Logical<br />
Link Layer 2) support. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3231)<br />
<br />
An information leak was discovered in the Linux kernel's receive<br />
message handling for the netrom address family. A local user could<br />
exploit this flaw to obtain sensitive information from the kernel's<br />
stack memory. (CVE-2013-3232)<br />
<br />
An information leak was discovered in the Linux kernel's nfc (near<br />
field communication) support. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3233)<br />
<br />
An information leak was discovered in the Linux kernel's Rose X.25<br />
protocol layer. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3234)<br />
<br />
An information leak was discovered in the Linux kernel's TIPC<br />
(Transparent Inter Process Communication) protocol implementation. A<br />
local user could exploit this flaw to examine potentially sensitive<br />
information from the kernel's stack memory. (CVE-2013-3235).<br />
<br />
Solution :<br />
<br />
Update the affected linux-image-3.5.0-34-generic package.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 4.9<br />
(CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N)<br />
CVSS Temporal Score : 3.6<br />
(CVSS2#E:U/RL:OF/RC:C)<br />
Public Exploit Available : false<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66903</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66902">
<title>Ubuntu 12.04 LTS : linux vulnerabilities (USN-1878-1)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Ubuntu host is missing one or more security-related patches.<br />
<br />
Description :<br />
<br />
An information leak was discovered in the Linux kernel when inotify is<br />
used to monitor the /dev/ptmx device. A local user could exploit this<br />
flaw to discover keystroke timing and potentially discover sensitive<br />
information like password length. (CVE-2013-0160)<br />
<br />
A flaw was discovered in the Linux kernel's perf events subsystem for<br />
Intel Sandy Bridge and Ivy Bridge processors. A local user could<br />
exploit this flaw to cause a denial of service (system crash).<br />
(CVE-2013-2146)<br />
<br />
An information leak was discovered in the Linux kernel's crypto API. A<br />
local user could exploit this flaw to examine potentially sensitive<br />
information from the kernel's stack memory. (CVE-2013-3076)<br />
<br />
An information leak was discovered in the Linux kernel's rcvmsg path<br />
for ATM (Asynchronous Transfer Mode). A local user could exploit this<br />
flaw to examine potentially sensitive information from the kernel's<br />
stack memory. (CVE-2013-3222)<br />
<br />
An information leak was discovered in the Linux kernel's recvmsg path<br />
for ax25 address family. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3223)<br />
<br />
An information leak was discovered in the Linux kernel's recvmsg path<br />
for the bluetooth address family. A local user could exploit this flaw<br />
to examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3224)<br />
<br />
An information leak was discovered in the Linux kernel's bluetooth<br />
rfcomm protocol support. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3225)<br />
<br />
An information leak was discovered in the Linux kernel's CAIF protocol<br />
implementation. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3227)<br />
<br />
An information leak was discovered in the Linux kernel's IRDA<br />
(infrared) support subsystem. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3228)<br />
<br />
An information leak was discovered in the Linux kernel's s390 - z/VM<br />
support. A local user could exploit this flaw to examine potentially<br />
sensitive information from the kernel's stack memory. (CVE-2013-3229)<br />
<br />
An information leak was discovered in the Linux kernel's llc (Logical<br />
Link Layer 2) support. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3231)<br />
<br />
An information leak was discovered in the Linux kernel's receive<br />
message handling for the netrom address family. A local user could<br />
exploit this flaw to obtain sensitive information from the kernel's<br />
stack memory. (CVE-2013-3232)<br />
<br />
An information leak was discovered in the Linux kernel's Rose X.25<br />
protocol layer. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3234)<br />
<br />
An information leak was discovered in the Linux kernel's TIPC<br />
(Transparent Inter Process Communication) protocol implementation. A<br />
local user could exploit this flaw to examine potentially sensitive<br />
information from the kernel's stack memory. (CVE-2013-3235).<br />
<br />
Solution :<br />
<br />
Update the affected packages.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 4.9<br />
(CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N)<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66902</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66901">
<title>Ubuntu 10.04 LTS : linux-ec2 vulnerabilities (USN-1877-1)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Ubuntu host is missing a security-related patch.<br />
<br />
Description :<br />
<br />
Andrew Honig reported a flaw in the way KVM (Kernel-based Virtual<br />
Machine) emulated the IOAPIC. A privileged guest user could exploit<br />
this flaw to read host memory or cause a denial of service (crash the<br />
host). (CVE-2013-1798)<br />
<br />
An information leak was discovered in the Linux kernel's rcvmsg path<br />
for ATM (Asynchronous Transfer Mode). A local user could exploit this<br />
flaw to examine potentially sensitive information from the kernel's<br />
stack memory. (CVE-2013-3222)<br />
<br />
An information leak was discovered in the Linux kernel's recvmsg path<br />
for ax25 address family. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3223)<br />
<br />
An information leak was discovered in the Linux kernel's recvmsg path<br />
for the bluetooth address family. A local user could exploit this flaw<br />
to examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3224)<br />
<br />
An information leak was discovered in the Linux kernel's bluetooth<br />
rfcomm protocol support. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3225)<br />
<br />
An information leak was discovered in the Linux kernel's IRDA<br />
(infrared) support subsystem. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3228)<br />
<br />
An information leak was discovered in the Linux kernel's s390 - z/VM<br />
support. A local user could exploit this flaw to examine potentially<br />
sensitive information from the kernel's stack memory. (CVE-2013-3229)<br />
<br />
An information leak was discovered in the Linux kernel's llc (Logical<br />
Link Layer 2) support. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3231)<br />
<br />
An information leak was discovered in the Linux kernel's receive<br />
message handling for the netrom address family. A local user could<br />
exploit this flaw to obtain sensitive information from the kernel's<br />
stack memory. (CVE-2013-3232)<br />
<br />
An information leak was discovered in the Linux kernel's Rose X.25<br />
protocol layer. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3234)<br />
<br />
An information leak was discovered in the Linux kernel's TIPC<br />
(Transparent Inter Process Communication) protocol implementation. A<br />
local user could exploit this flaw to examine potentially sensitive<br />
information from the kernel's stack memory. (CVE-2013-3235).<br />
<br />
Solution :<br />
<br />
Update the affected linux-image-2.6.32-353-ec2 package.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 6.2<br />
(CVSS2#AV:A/AC:H/Au:N/C:C/I:N/A:C)<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66901</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66900">
<title>Ubuntu 10.04 LTS : linux vulnerabilities (USN-1876-1)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Ubuntu host is missing one or more security-related patches.<br />
<br />
Description :<br />
<br />
Andrew Honig reported a flaw in the way KVM (Kernel-based Virtual<br />
Machine) emulated the IOAPIC. A privileged guest user could exploit<br />
this flaw to read host memory or cause a denial of service (crash the<br />
host). (CVE-2013-1798)<br />
<br />
An information leak was discovered in the Linux kernel's rcvmsg path<br />
for ATM (Asynchronous Transfer Mode). A local user could exploit this<br />
flaw to examine potentially sensitive information from the kernel's<br />
stack memory. (CVE-2013-3222)<br />
<br />
An information leak was discovered in the Linux kernel's recvmsg path<br />
for ax25 address family. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3223)<br />
<br />
An information leak was discovered in the Linux kernel's recvmsg path<br />
for the bluetooth address family. A local user could exploit this flaw<br />
to examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3224)<br />
<br />
An information leak was discovered in the Linux kernel's bluetooth<br />
rfcomm protocol support. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3225)<br />
<br />
An information leak was discovered in the Linux kernel's IRDA<br />
(infrared) support subsystem. A local user could exploit this flaw to<br />
examine potentially sensitive information from the kernel's stack<br />
memory. (CVE-2013-3228)<br />
<br />
An information leak was discovered in the Linux kernel's s390 - z/VM<br />
support. A local user could exploit this flaw to examine potentially<br />
sensitive information from the kernel's stack memory. (CVE-2013-3229)<br />
<br />
An information leak was discovered in the Linux kernel's llc (Logical<br />
Link Layer 2) support. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3231)<br />
<br />
An information leak was discovered in the Linux kernel's receive<br />
message handling for the netrom address family. A local user could<br />
exploit this flaw to obtain sensitive information from the kernel's<br />
stack memory. (CVE-2013-3232)<br />
<br />
An information leak was discovered in the Linux kernel's Rose X.25<br />
protocol layer. A local user could exploit this flaw to examine<br />
potentially sensitive information from the kernel's stack memory.<br />
(CVE-2013-3234)<br />
<br />
An information leak was discovered in the Linux kernel's TIPC<br />
(Transparent Inter Process Communication) protocol implementation. A<br />
local user could exploit this flaw to examine potentially sensitive<br />
information from the kernel's stack memory. (CVE-2013-3235).<br />
<br />
Solution :<br />
<br />
Update the affected packages.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 6.2<br />
(CVSS2#AV:A/AC:H/Au:N/C:C/I:N/A:C)<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66900</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66899">
<title>Mandriva Linux Security Advisory : apache (MDVSA-2013:174)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Mandriva Linux host is missing one or more security<br />
updates.<br />
<br />
Description :<br />
<br />
Multiple vulnerabilities has been found and corrected in apache :<br />
<br />
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server<br />
2.2.x before 2.2.25 writes data to a log file without sanitizing<br />
non-printable characters, which might allow remote attackers to<br />
execute arbitrary commands via an HTTP request containing an escape<br />
sequence for a terminal emulator (CVE-2013-1862).<br />
<br />
A buffer overflow when reading digest password file with very long<br />
lines in htdigest was discovered (PR 54893).<br />
<br />
The updated packages have been patched to correct these issues.<br />
<br />
See also :<br />
<br />
<a href="https://bugzilla.redhat.com/show_bug.cgi?id=953729" target="_blank">https://bugzilla.redhat.com/show_bug.cgi?id=953729</a><br />
<a href="https://issues.apache.org/bugzilla/show_bug.cgi?id=54893" target="_blank">https://issues.apache.org/bugzilla/show_bug.cgi?id=54893</a><br />
<br />
Solution :<br />
<br />
Update the affected packages.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 5.1<br />
(CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P)<br />
CVSS Temporal Score : 4.2<br />
(CVSS2#E:F/RL:OF/RC:C)<br />
Public Exploit Available : true<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66899</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66898">
<title>Jenkins &lt; 1.514 / 1.509.1 and Jenkins Enterprise 1.466.x / 1.480.x &lt; 1.466.14.1 / 1.480.4.1 Multiple Vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote web server hosts a job scheduling / management system that<br />
is affected by multiple vulnerabilities.<br />
<br />
Description :<br />
<br />
The remote web server hosts a version of Jenkins or Jenkins Enterprise<br />
that is affected by multiple vulnerabilities :<br />
<br />
  - The included component 'ZeroClipboard' contains an<br />
    error in the file 'ZeroClipboard10.swf' that could<br />
    allow cross-site scripting attacks.<br />
    (CVE-2013-1808)<br />
<br />
  - An unspecified cross-site scripting error exists.<br />
    (CVE-2013-2033)<br />
<br />
  - Multiple errors exist that could lead to cross-site<br />
    request forgery attacks, thus allowing an attacker to<br />
    trick an administrator into executing arbitrary code.<br />
    (CVE-2013-2034)<br />
<br />
See also :<br />
<br />
<a href="http://www.nessus.org/u?832b8cbc" target="_blank">http://www.nessus.org/u?832b8cbc</a><br />
<a href="http://www.nessus.org/u?586d4f60" target="_blank">http://www.nessus.org/u?586d4f60</a><br />
<br />
Solution :<br />
<br />
Upgrade to Jenkins 1.514 / 1.509.1, Jenkins Enterprise 1.466.14.1 /<br />
1.480.4.1 or later.<br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 8.8<br />
(CVSS2#AV:N/AC:M/Au:N/C:N/I:C/A:C)<br />
CVSS Temporal Score : 7.3<br />
(CVSS2#E:F/RL:OF/RC:C)<br />
Public Exploit Available : true<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66898</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66897">
<title>VMware vCenter Chargeback Manager Remote Code Execution (VMSA-2013-0008)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Windows host has an application installed that is<br />
potentially affected by a remote code execution vulnerability.<br />
<br />
Description :<br />
<br />
The version of VMware vCenter Chargeback Manager installed on the<br />
remote Windows host is potentially affected by a remote code execution<br />
vulnerability due to a flaw in the handling of file uploads.  By<br />
exploiting this flaw, a remote, unauthenticated attacker could execute<br />
arbitrary code subject to the privileges of the user running the<br />
application.<br />
<br />
See also :<br />
<br />
<a href="http://lists.vmware.com/pipermail/security-announce/2013/000217.html" target="_blank">http://lists.vmware.com/pipermail/security-announce/2013/000217.html</a><br />
<br />
Solution :<br />
<br />
Upgrade to VMware vCenter Chargeback Manager 2.5.1 or later.<br />
<br />
Risk factor :<br />
<br />
Critical / CVSS Base Score : 10.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)<br />
CVSS Temporal Score : 7.4<br />
(CVSS2#E:U/RL:OF/RC:C)<br />
Public Exploit Available : false<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66897</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=66896">
<title>VMware vCenter Chargeback Manager Installed</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
A cost reporting application is installed on the remote Windows<br />
host.<br />
<br />
Description :<br />
<br />
VMware vCenter Chargeback Manager, a cost reporting application, is<br />
installed on the remote Windows host.<br />
<br />
See also :<br />
<br />
<a href="http://www.nessus.org/u?66849826" target="_blank">http://www.nessus.org/u?66849826</a><br />
<br />
Solution :<br />
<br />
n/a<br />
<br />
Risk factor :<br />
<br />
None<br />
<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=66896</link>
<dc:date>?</dc:date>
</item>
</rdf:RDF>

