Fedora 14 : libHX-3.6-1.fc14 / pam_mount-2.5-1.fc14 (2010-12950)

This script is Copyright (C) 2010-2016 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing one or more security updates.

Description :

Update to libHX 3.6 fixing a buffer overflow in HX_split() :

-
http://libhx.git.sourceforge.net/git/gitweb.cgi?p=libhx/
libhx;a=commitdiff;h=904a46f90d

pam_mount v2.5 (August 10 2010) ===============================
Changes :

- mount.crypt: fix incorrect processing of binary files in
keyfile passthrough

- call mount.crypt by means of mount -t crypt (selinux),
same for umount

- reorder the default path to search in /usr/local
first, then /usr, /

- config: add missing fd0ssh command to restore volumes
using ssh

- ofl is now run as a separate process (selinux policy
simplification)

libHX v3.6 (August 16 2010) =========================== Fixed :

- bitmap: set/clear/test had no effect due to wrong type
selection

- bitmap: avoid left-shift larger than type on 64-bit

- string: fixed buffer overflow in HX_split when too few
fields were present in the input

libHX 3.5 (August 01 2010) ========================== Fixed :

- format2: failure to skip escaped char in '%(echo foo\
bar)' was corrected

- proc: properly check for HXPROC_STDx--HXPROC_STDx_NULL
overlap

- strquote: do not cause allocation with invalid format
numbers Enhancements :

- format2: add the %(exec) function

- format2: add the %(shell) function

- format2: security feature for %(exec) and %(shell)

- format2: add the %(snl) function

- string: HX_strquote gained HXQUOTE_LDAPFLT (LDAP
search filter) support

- string: HX_strquote gained HXQUOTE_LDAPRDN (LDAP
relative DN) support Changes :

- format1: removed older formatter in favor of format2

- format2: add check for empty key

- format2: function-specific delimiters

- format2: do nest-counting even with normal parentheses

- format2: check for zero-argument function calls

- hashmap: do not needlessy change TID when no reshape
was done

- string: HX_basename (the fast variant) now recognizes
the root directory

- string: HX_basename now returns the trailing component
with slashes instead of everything after the last
slash (which may have been nothing)

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://www.nessus.org/u?6bfbed59
https://bugzilla.redhat.com/show_bug.cgi?id=625866
http://www.nessus.org/u?35fb2b43
http://www.nessus.org/u?f4b7ea31

Solution :

Update the affected libHX and / or pam_mount packages.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.7
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Fedora Local Security Checks

Nessus Plugin ID: 50389 ()

Bugtraq ID: 42592

CVE ID: CVE-2010-2947

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now