Fedora 8 : librapi-0.11-1.fc8 / librra-0.11-1.fc8 / libsynce-0.11-2.fc8 / odccm-0.11-1.fc8 / etc (2008-0680)

critical Nessus Plugin ID 31361

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora host is missing one or more security updates :

librra-0.11-1.fc8 :

- Wed Jan 9 2008 Andreas Bierfert <andreas.bierfert[AT]lowlatency.de>

- 0.11-1

- version upgrade

- Fri Dec 21 2007 Andreas Bierfert <andreas.bierfert[AT]lowlatency.de>

- 0.10.0-2

- rework BR

- Wed May 9 2007 Aurelien Bompard <abompard at fedoraproject.org> 0.10.0-1

- version 0.10.0

synce-serial-0.11-1.fc8 :

- Wed Jan 9 2008 Andreas Bierfert <andreas.bierfert[AT]lowlatency.de>

- 0.11-1

- version upgrade

- remove dependency on vdccm

- Fri Dec 21 2007 Andreas Bierfert <andreas.bierfert[AT]lowlatency.de>

- correct Requires

- fix #249031 udev rule

- Wed May 9 2007 Aurelien Bompard <abompard at fedoraproject.org> 0.10.0-1

- version 0.10.0

librapi-0.11-1.fc8 / libsynce-0.11-2.fc8 / odccm-0.11-1.fc8 / pywbxml-0.1-2.fc8 / synce-gnome-0.11-2.fc8 / synce-kpm-0.11-3.fc8 / synce-sync-engine-0.11-6.fc8 / vdccm-0.10.1-1.fc8 :

- Bug #436023 - CVE-2007-6703 vdccm 0.10.1 fixes a security vulnerability

- Bug #436024 - CVE-2008-1136 vdccm insufficient escaping of shell metacharacters

wbxml2-0.9.2-12.fc8 :

- Sat Jan 12 2008 Andreas Bierfert <andreas.bierfert[AT]lowlatency.de>

- 0.9.2-12

- pkgconfig also needs libxml2-devel

- Sat Jan 12 2008 Andreas Bierfert <andreas.bierfert[AT]lowlatency.de>

- 0.9.2-11

- fix devel requires

- Mon Jan 7 2008 Andreas Bierfert <andreas.bierfert[AT]lowlatency.de>

- 0.9.2-10

- add synce patches

synce-gnomevfs-0.11-1.fc8 :

- Wed Jan 9 2008 Andreas Bierfert <andreas.bierfert[AT]lowlatency.de>

- 0.11-1

- version upgrade

- Sun Dec 23 2007 Andreas Bierfert <andreas.bierfert[AT]lowlatency.de>

- 0.10.0-1

- version upgrade

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected packages.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=436023

https://bugzilla.redhat.com/show_bug.cgi?id=436024

http://www.nessus.org/u?ce10b648

http://www.nessus.org/u?57977440

http://www.nessus.org/u?4e621654

http://www.nessus.org/u?ea2d8d86

http://www.nessus.org/u?bdbfd06b

http://www.nessus.org/u?ad76168a

http://www.nessus.org/u?27681e96

http://www.nessus.org/u?541d9357

http://www.nessus.org/u?74aa5c19

http://www.nessus.org/u?e06e10ea

http://www.nessus.org/u?f16ba58e

http://www.nessus.org/u?923abeb6

Plugin Details

Severity: Critical

ID: 31361

File Name: fedora_2008-0680.nasl

Version: 1.20

Type: local

Agent: unix

Published: 3/7/2008

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:librapi, p-cpe:/a:fedoraproject:fedora:librra, p-cpe:/a:fedoraproject:fedora:libsynce, p-cpe:/a:fedoraproject:fedora:odccm, p-cpe:/a:fedoraproject:fedora:pywbxml, p-cpe:/a:fedoraproject:fedora:synce-gnome, p-cpe:/a:fedoraproject:fedora:synce-gnomevfs, p-cpe:/a:fedoraproject:fedora:synce-kpm, p-cpe:/a:fedoraproject:fedora:synce-serial, p-cpe:/a:fedoraproject:fedora:synce-sync-engine, p-cpe:/a:fedoraproject:fedora:vdccm, p-cpe:/a:fedoraproject:fedora:wbxml2, cpe:/o:fedoraproject:fedora:8

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/6/2008

Vulnerability Publication Date: 3/4/2008

Exploitable With

Core Impact

Reference Information

CVE: CVE-2007-6703, CVE-2008-1136

BID: 28141

CWE: 20, 94

FEDORA: 2008-0680