Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 10: 2009-8799 Moderate: OCS Inventory SQL Injection Risk

fedora
Calendar Grey August 20, 2009
Dist Fedora Esm H88
A critical security flaw in OCS Inventory for Fedora 10 has been identified, alongside key information and recommendations.
A security issue has been found in GUI https://seclists.org/fulldisclosure/2009/Aug/143

Summary

Open Computer and Software Inventory Next Generation is an application

designed to help a network or system administrator keep track of the

computers configuration and software that are installed on the network.

OCS Inventory is also able to detect all active devices on your network,

such as switch, router, network printer and unattended devices.

OCS Inventory NG includes package deployment feature on client computers.

ocsinventory is a metapackage that will install the communication server,

the administration console and the database server (MySQL).

Update Information:

A security issue has been found in GUI https://seclists.org/fulldisclosure/2009/Aug/143

Change Log

* Mon Aug 17 2009 Remi Collet 1.02.1-3 - add ChangeLog - Security Fixes (internal version 5003) Bug #517837 * Sat May 30 2009 Remi Collet 1.02.1-1 - update to OCS Inventory NG 1.02.1 - Security Fixes (internal version 5003) * Mon Apr 20 2009 Remi Collet 1.02-1 - update to OCS Inventory NG 1.02 final release (internal version 5003) * Sun Jan 18 2009 Remi Collet 1.02-0.10.rc3.el4.1 - fix php-xml > php-domxml in EL-4 * Sun Jan 11 2009 Remi Collet 1.02-0.10.rc3 - add r1447 and r1462 patch - change log selinux context (httpd_log_t)

References


[ 1 ] Bug #517837 - OCS Inventory NG: SQL injection in machine blacklisting https://bugzilla.redhat.com/show_bug.cgi?id=517837

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update ocsinventory' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ocsinventory
Product: Fedora 10
Version: 1.02.1
Release: 3.fc10
Summary: Open Computer and Software Inventory Next Generation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here