Fedora 13 : libHX-3.6-1.fc13 / pam_mount-2.5-1.fc13 (2010-13127)

This script is Copyright (C) 2010-2016 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing one or more security updates.

Description :

Update to libHX 3.6 fixing a buffer overflow in HX_split(): *
http://libhx.gi
t.sourceforge.net/git/gitweb.cgi?p=libhx/libhx;a=commitdiff;h=904a46f9
0d pam_mount v2.5 (August 10 2010) ===============================
Changes: - mount.crypt: fix incorrect processing of binary files in
keyfile passthrough - call mount.crypt by means of mount -t crypt
(selinux), same for umount - reorder the default path to search in
/usr/local first, then /usr, / - config: add missing fd0ssh command to
restore volumes using ssh - ofl is now run as a separate process
(selinux policy simplification) libHX v3.6 (August 16 2010)
=========================== Fixed: - bitmap: set/clear/test had no
effect due to wrong type selection - bitmap: avoid left-shift larger
than type on 64-bit

- string: fixed buffer overflow in HX_split when too few
fields were present in the input libHX 3.5 (August 01
2010) ========================== Fixed: - format2:
failure to skip escaped char in '%(echo foo\ bar)' was
corrected - proc: properly check for
HXPROC_STDx--HXPROC_STDx_NULL overlap - strquote: do not
cause allocation with invalid format numbers
Enhancements: - format2: add the %(exec) function -
format2: add the %(shell) function - format2: security
feature for %(exec) and %(shell) - format2: add the
%(snl) function - string: HX_strquote gained
HXQUOTE_LDAPFLT (LDAP search filter) support - string:
HX_strquote gained HXQUOTE_LDAPRDN (LDAP relative DN)
support Changes: - format1: removed older formatter in
favor of format2 - format2: add check for empty key -
format2: function-specific delimiters - format2: do
nest-counting even with normal parentheses - format2:
check for zero-argument function calls

- hashmap: do not needlessy change TID when no reshape was
done - string: HX_basename (the fast variant) now
recognizes the root directory - string: HX_basename now
returns the trailing component with slashes instead of
everything after the last slash (which may have been
nothing)

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://libhx.gi
https://bugzilla.redhat.com/show_bug.cgi?id=625866
http://www.nessus.org/u?434f277f
http://www.nessus.org/u?6cd82631

Solution :

Update the affected libHX and / or pam_mount packages.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.7
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Fedora Local Security Checks

Nessus Plugin ID: 49105 (fedora_2010-13127.nasl)

Bugtraq ID: 42592

CVE ID: CVE-2010-2947

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now