RHEL 6 : libguestfs (RHSA-2012:0774)

medium Nessus Plugin ID 64040

Synopsis

The remote Red Hat host is missing a security update.

Description

The remote Redhat Enterprise Linux 6 host has packages installed that are affected by a vulnerability as referenced in the RHSA-2012:0774 advisory.

- libguestfs: virt-edit creates a new file, when it is used leading to loss of file attributes (permissions, owner, SELinux context etc.) (CVE-2012-2690)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?25c51fb6

http://www.nessus.org/u?cf3d5852

https://access.redhat.com/errata/RHSA-2012:0774

https://access.redhat.com/security/updates/classification/#low

https://bugzilla.redhat.com/show_bug.cgi?id=647174

https://bugzilla.redhat.com/show_bug.cgi?id=679737

https://bugzilla.redhat.com/show_bug.cgi?id=719879

https://bugzilla.redhat.com/show_bug.cgi?id=729076

https://bugzilla.redhat.com/show_bug.cgi?id=731742

https://bugzilla.redhat.com/show_bug.cgi?id=741183

https://bugzilla.redhat.com/show_bug.cgi?id=760221

https://bugzilla.redhat.com/show_bug.cgi?id=769359

https://bugzilla.redhat.com/show_bug.cgi?id=785305

https://bugzilla.redhat.com/show_bug.cgi?id=785668

https://bugzilla.redhat.com/show_bug.cgi?id=789960

https://bugzilla.redhat.com/show_bug.cgi?id=790958

https://bugzilla.redhat.com/show_bug.cgi?id=795322

https://bugzilla.redhat.com/show_bug.cgi?id=796520

https://bugzilla.redhat.com/show_bug.cgi?id=797760

https://bugzilla.redhat.com/show_bug.cgi?id=798197

https://bugzilla.redhat.com/show_bug.cgi?id=798980

https://bugzilla.redhat.com/show_bug.cgi?id=799695

https://bugzilla.redhat.com/show_bug.cgi?id=799798

https://bugzilla.redhat.com/show_bug.cgi?id=801273

https://bugzilla.redhat.com/show_bug.cgi?id=801788

https://bugzilla.redhat.com/show_bug.cgi?id=803699

https://bugzilla.redhat.com/show_bug.cgi?id=807557

https://bugzilla.redhat.com/show_bug.cgi?id=807905

https://bugzilla.redhat.com/show_bug.cgi?id=809401

https://bugzilla.redhat.com/show_bug.cgi?id=811112

https://bugzilla.redhat.com/show_bug.cgi?id=811117

https://bugzilla.redhat.com/show_bug.cgi?id=811673

https://bugzilla.redhat.com/show_bug.cgi?id=812092

https://bugzilla.redhat.com/show_bug.cgi?id=813329

https://bugzilla.redhat.com/show_bug.cgi?id=831117

Plugin Details

Severity: Medium

ID: 64040

File Name: redhat-RHSA-2012-0774.nasl

Version: 1.18

Type: local

Agent: unix

Published: 1/24/2013

Updated: 4/27/2024

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2012-2690

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:libguestfs, p-cpe:/a:redhat:enterprise_linux:libguestfs-devel, p-cpe:/a:redhat:enterprise_linux:libguestfs-java, p-cpe:/a:redhat:enterprise_linux:libguestfs-java-devel, p-cpe:/a:redhat:enterprise_linux:libguestfs-javadoc, p-cpe:/a:redhat:enterprise_linux:libguestfs-tools, p-cpe:/a:redhat:enterprise_linux:libguestfs-tools-c, p-cpe:/a:redhat:enterprise_linux:ocaml-libguestfs, p-cpe:/a:redhat:enterprise_linux:ocaml-libguestfs-devel, p-cpe:/a:redhat:enterprise_linux:perl-sys-guestfs, p-cpe:/a:redhat:enterprise_linux:python-libguestfs, p-cpe:/a:redhat:enterprise_linux:ruby-libguestfs, cpe:/o:redhat:enterprise_linux:6

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 6/20/2012

Vulnerability Publication Date: 6/29/2012

Reference Information

CVE: CVE-2012-2690

BID: 53932

RHSA: 2012:0774