OracleVM 3.3 / 3.4 : coreutils (OVMSA-2017-0052)

medium Nessus Plugin ID 99079

Synopsis

The remote OracleVM host is missing one or more security updates.

Description

The remote OracleVM system is missing necessary patches to address critical security updates :

- clean up empty file if cp is failed [Orabug 15973168]

- pure rebuild to bring back support for acl_extended_file_nofollow on x86_64

- su: deny killing other processes with root privileges (CVE-2017-2616)

- fix the functionality of 'sort -h -k ...' in multi-byte locales (#1357979)

- use correct path to grep(1) in colorls.sh (#1376892)

- make colorls.sh compatible with ksh (#1321643)

- sed should actually be /bin/sed (related #1222140)

- colorls.sh,colorls.csh - call utilities with complete path (#1222140)

- mkdir, mkfifo, mknod - respect default umask/acls when COREUTILS_CHILD_DEFAULT_ACLS envvar is set (to match rhel 7 behaviour,

- ls: improve efficiency on filesystems without support for ACLs, xattrs or SELinux (#1248141)

- su: suppress PAM info messages for -c or non-login sessions (#1267588)

- tail, stat: recognize several new filesystems - up2date by Jan 1st 2016 (#1280333)

- du: improve du error message of coreutils commands in a chrooted environment (patch by Boris Ranto) (#1086916)

- su: fix incorrect message printing when su is killed (#1147532)

Solution

Update the affected coreutils / coreutils-libs packages.

See Also

http://www.nessus.org/u?40167d41

http://www.nessus.org/u?7493a037

Plugin Details

Severity: Medium

ID: 99079

File Name: oraclevm_OVMSA-2017-0052.nasl

Version: 3.6

Type: local

Published: 3/30/2017

Updated: 1/4/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.5

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:N/A:C

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:coreutils, p-cpe:/a:oracle:vm:coreutils-libs, cpe:/o:oracle:vm_server:3.3, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 3/29/2017

Vulnerability Publication Date: 7/27/2018

Reference Information

CVE: CVE-2017-2616