Virtuozzo 7 : anaconda / anaconda-core / anaconda-dracut / etc (VZA-2017-012)

high Nessus Plugin ID 97983

Synopsis

The remote Virtuozzo host is missing multiple security updates.

Description

According to the versions of the anaconda / anaconda-core / anaconda-dracut / etc packages installed, the Virtuozzo installation on the remote host is affected by the following vulnerabilities :

- A flaw found in the way prl-vzvncserver parsed terminal escape sequences that could allow a remote attacker authenticated with the VNC password or a user logged in to a container as root to execute arbitrary code as host root.

- A flaw was found in prl-vzvncserver that could allow a remote attacker authenticated with the VNC password or a user logged in to a container as root to crash prl-vzvncserver by exploiting the way it handled overlapping memory areas.

- A flaw was found in prl-vzvncserver that could allow a remote attacker authenticated with the VNC password or a user logged in to a container as root to crash prl-vzvncserver by executing a specially crafted command to overwrite a small memory region of the prl-vzvncserver process.

- A flaw was found in prl-vzvncserver that could allow a remote attacker authenticated with the VNC password or a user logged in to a container as root to crash prl-vzvncserver by executing a specially crafted command to cause allocation of a huge amount of memory.

Note that Tenable Network Security has extracted the preceding description block directly from the Virtuozzo security advisory.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected anaconda / anaconda-core / anaconda-dracut / etc packages.

See Also

https://help.virtuozzo.com/customer/portal/articles/2759546

Plugin Details

Severity: High

ID: 97983

File Name: Virtuozzo_VZA-2017-012.nasl

Version: 1.7

Type: local

Published: 3/27/2017

Updated: 1/4/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:virtuozzo:virtuozzo:vzctl, p-cpe:/a:virtuozzo:virtuozzo:vzlicutils, p-cpe:/a:virtuozzo:virtuozzo:vzmigrate, cpe:/o:virtuozzo:virtuozzo:7, p-cpe:/a:virtuozzo:virtuozzo:anaconda, p-cpe:/a:virtuozzo:virtuozzo:anaconda-core, p-cpe:/a:virtuozzo:virtuozzo:anaconda-dracut, p-cpe:/a:virtuozzo:virtuozzo:anaconda-gui, p-cpe:/a:virtuozzo:virtuozzo:anaconda-tui, p-cpe:/a:virtuozzo:virtuozzo:anaconda-widgets, p-cpe:/a:virtuozzo:virtuozzo:anaconda-widgets-devel, p-cpe:/a:virtuozzo:virtuozzo:libprlcommon, p-cpe:/a:virtuozzo:virtuozzo:libprlcommon-devel, p-cpe:/a:virtuozzo:virtuozzo:libprlsdk, p-cpe:/a:virtuozzo:virtuozzo:libprlsdk-devel, p-cpe:/a:virtuozzo:virtuozzo:libprlsdk-headers, p-cpe:/a:virtuozzo:virtuozzo:libprlsdk-python, p-cpe:/a:virtuozzo:virtuozzo:libprlxmlmodel, p-cpe:/a:virtuozzo:virtuozzo:libprlxmlmodel-devel, p-cpe:/a:virtuozzo:virtuozzo:libvcmmd, p-cpe:/a:virtuozzo:virtuozzo:libvcmmd-devel, p-cpe:/a:virtuozzo:virtuozzo:libvzctl, p-cpe:/a:virtuozzo:virtuozzo:libvzctl-devel, p-cpe:/a:virtuozzo:virtuozzo:pdrs, p-cpe:/a:virtuozzo:virtuozzo:pfcache, p-cpe:/a:virtuozzo:virtuozzo:prl-disp-backup, p-cpe:/a:virtuozzo:virtuozzo:prl-disp-legacy, p-cpe:/a:virtuozzo:virtuozzo:prl-disp-service, p-cpe:/a:virtuozzo:virtuozzo:prl-disp-service-tests, p-cpe:/a:virtuozzo:virtuozzo:prl-vzvncserver, p-cpe:/a:virtuozzo:virtuozzo:prlctl, p-cpe:/a:virtuozzo:virtuozzo:shaman, p-cpe:/a:virtuozzo:virtuozzo:sles-11-x86_64-ez, p-cpe:/a:virtuozzo:virtuozzo:vcmmd, p-cpe:/a:virtuozzo:virtuozzo:vcmmd-policies, p-cpe:/a:virtuozzo:virtuozzo:vmauth, p-cpe:/a:virtuozzo:virtuozzo:vstorage-anaconda-addon, p-cpe:/a:virtuozzo:virtuozzo:vstorage-aps, p-cpe:/a:virtuozzo:virtuozzo:vstorage-chunk-server, p-cpe:/a:virtuozzo:virtuozzo:vstorage-client, p-cpe:/a:virtuozzo:virtuozzo:vstorage-client-devel, p-cpe:/a:virtuozzo:virtuozzo:vstorage-core-devel, p-cpe:/a:virtuozzo:virtuozzo:vstorage-ctl, p-cpe:/a:virtuozzo:virtuozzo:vstorage-firewall-cfg, p-cpe:/a:virtuozzo:virtuozzo:vstorage-iscsi, p-cpe:/a:virtuozzo:virtuozzo:vstorage-libs-shared, p-cpe:/a:virtuozzo:virtuozzo:vstorage-metadata-server, p-cpe:/a:virtuozzo:virtuozzo:vstorage-ostor, p-cpe:/a:virtuozzo:virtuozzo:vstorage-tests, p-cpe:/a:virtuozzo:virtuozzo:vstorage-www, p-cpe:/a:virtuozzo:virtuozzo:vz-guest-tools-win

Required KB Items: Host/local_checks_enabled, Host/Virtuozzo/release, Host/Virtuozzo/rpm-list

Patch Publication Date: 3/6/2017