Oracle Secure Global Desktop Multiple Vulnerabilities (July 2014 CPU)

High Nessus Plugin ID 76570


The remote host has a version of Oracle Secure Global Desktop that is affected by multiple vulnerabilities.


The remote host has a version of Oracle Secure Global Desktop that is version 4.63, 4.71, 5.0 or 5.1. It is, therefore, affected by the following vulnerabilities :

- Apache Tomcat does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of a request's length and conduct request-smuggling attacks.

- in Apache Tomcat does not consider the 'disableURLRewriting' setting when handling session ID in a URL, allowing a remote attacker to conduct session fixation attacks via a crafted URL.

- The 'log_cookie' function in mod_log_config.c of Apache will not handle specially crafted cookies during truncation, allowing a remote attacker to cause a denial of service via a segmentation fault. (CVE-2014-0098)

- Multiple integer overflows within X.Org libXfont that could allow remote font servers to execute arbitrary code via a crafted xfs reply, which triggers a buffer overflow. (CVE-2014-0211)

- OpenSSL does not properly restrict processing of 'ChangeCipherSpec' messages which allows man-in-the-middle attackers to trigger use of a zero-length master key and consequently hijack sessions or obtain sensitive information via a crafted TLS handshake. (CVE-2014-0224)

- An unspecified flaw related to the Workspace Web Application subcomponent could allow a remote attacker to impact integrity. (CVE-2014-4232)


Apply the appropriate patch according to the July 2014 Oracle Critical Patch Update advisory.

See Also

Plugin Details

Severity: High

ID: 76570

File Name: oracle_secure_global_desktop_jul_2014_cpu.nasl

Version: $Revision: 1.7 $

Type: local

Family: Misc.

Published: 2014/07/17

Modified: 2016/05/20

Dependencies: 70729

Risk Information

Risk Factor: High


Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:virtualization_secure_global_desktop

Required KB Items: Host/Oracle_Secure_Global_Desktop/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/07/15

Vulnerability Publication Date: 2014/02/26

Exploitable With

Core Impact

Reference Information

CVE: CVE-2013-4286, CVE-2014-0033, CVE-2014-0098, CVE-2014-0211, CVE-2014-0224, CVE-2014-4232

BID: 65769, 65773, 66303, 67382, 67899, 68606

OSVDB: 103705, 103708, 104580, 106980, 107729

CERT: 978508