This script is Copyright (C) 2007-2012 Tenable Network Security, Inc.
Synopsis :
The remote SuSE 10 host is missing a security-related patch.
Description :
The following issues have been fixed :
- missing open_basedir and safe_mode restriction.
(CVE-2007-3007)
- chunk_split() integer overflow. (CVE-2007-2872)
- DoS condition in libgd's image processing.
(CVE-2007-2756)
- possible super-global overwrite inside
import_request_variables(). (CVE-2007-1396)
- buffer overflow inside user_filter_factory_create().
(CVE-2007-2511)
- remotely trigger-able buffer overflow inside bundled
libxmlrpc. (CVE-2007-1864)
- CRLF injection inside ftp_putcmd(). (CVE-2007-2509)
- remotely trigger-able buffer overflow inside
make_http_soap_request(). (CVE-2007-2510)
- MOPB-41-2007:PHP 5 sqlite_udf_decode_binary() Buffer
Overflow Vulnerability. (CVE-2007-0906)
- MOPB-03-2007: deep recursion DoS (CVE-2007-1285)
See also :
http://support.novell.com/security/cve/CVE-2007-0906.html
http://support.novell.com/security/cve/CVE-2007-1285.html
http://support.novell.com/security/cve/CVE-2007-1396.html
http://support.novell.com/security/cve/CVE-2007-1864.html
http://support.novell.com/security/cve/CVE-2007-2509.html
http://support.novell.com/security/cve/CVE-2007-2510.html
http://support.novell.com/security/cve/CVE-2007-2511.html
http://support.novell.com/security/cve/CVE-2007-2756.html
http://support.novell.com/security/cve/CVE-2007-2872.html
http://support.novell.com/security/cve/CVE-2007-3007.html
Solution :
Apply ZYPP patch number 3754.
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
Family: SuSE Local Security Checks
Nessus Plugin ID: 29552 ()
CVE ID: CVE-2007-0906
CVE-2007-1285
CVE-2007-1396
CVE-2007-1864
CVE-2007-2509
CVE-2007-2510
CVE-2007-2511
CVE-2007-2756
CVE-2007-2872
CVE-2007-3007