Fedora 16 : libsocialweb-0.25.20-1.fc16 / rest-0.7.12-1.fc16 (2011-15833)

This script is Copyright (C) 2011-2015 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing one or more security updates.

Description :

CVE-2011-4129

A security flaw was found in the way the libsocialweb, a social
network data aggregator, performed its initialization when this
service start was initiated by the dbus daemon. Due to a deficiency in
a way the libsocialweb service was initialized, an untrusted (non-SSL)
network connection has been opened to remote Twitter service servers
without explicit approval of the user, running the libsocialweb
service on the local host. A remote attacker could use this flaw to
conduct various MITM attacks and potentially alter integrity of the
user account in question.

- libsocialweb: The views will try and fetch content from
the web service even if they aren't configured.

- rest: enforce that the SSL certificate is valid

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

https://bugzilla.redhat.com/show_bug.cgi?id=752022
http://www.nessus.org/u?7ae11894
http://www.nessus.org/u?f1e60201

Solution :

Update the affected libsocialweb and / or rest packages.

Risk factor :

Medium / CVSS Base Score : 5.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N)

Family: Fedora Local Security Checks

Nessus Plugin ID: 56940 ()

Bugtraq ID:

CVE ID: CVE-2011-4129

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now