OracleVM 3.3 : rsyslog (OVMSA-2014-0030)

High Nessus Plugin ID 79545


The remote OracleVM host is missing a security update.


The remote OracleVM system is missing necessary patches to address critical security updates :

- use setsid to get a controlling session and process group [Orabug: 17346261] (Todd Vierling)

- fix (CVE-2014-3634) resolves: #1149148

- drop patch 5 which introduced a regression resolves:
#927405 reverts: #847568

- add a patch to prevent 'RepeatedMsgReduction' causing missing hostnames resolves: #893197

- add a patch to enable specifying UID/GID as a number resolves: #886117

- add a patch to prevent a segfault in gssapi resolves:


Update the affected rsyslog package.

See Also

Plugin Details

Severity: High

ID: 79545

File Name: oraclevm_OVMSA-2014-0030.nasl

Version: $Revision: 1.5 $

Type: local

Published: 2014/11/26

Modified: 2017/02/14

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:POC/RL:OF/RC:ND

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:rsyslog, cpe:/o:oracle:vm_server:3.3

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/11/04

Reference Information

CVE: CVE-2014-3634

BID: 70187

OSVDB: 112338