Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora: 2009-5764 Critical Advisory for OCS Inventory SQL Injection

fedora
Calendar Grey June 2, 2009
Dist Fedora Esm H88
The new patch version 1.03.0-2.fc10 for Fedora addresses vulnerabilities in ocsinventory, specifically SQL injection risks and improves authentication procedures
2 Security fixes - CVE-2009-1769 OCS Inventory NG: Authentication result varies for existent and non-existent users - SQL injection and Unauthenticated Arbitrary File Read So...

Summary

Open Computer and Software Inventory Next Generation is an application

designed to help a network or system administrator keep track of the

computers configuration and software that are installed on the network.

OCS Inventory is also able to detect all active devices on your network,

such as switch, router, network printer and unattended devices.

OCS Inventory NG includes package deployment feature on client computers.

ocsinventory is a metapackage that will install the communication server,

the administration console and the database server (MySQL).

Update Information:

2 Security fixes - CVE-2009-1769 OCS Inventory NG: Authentication result varies for existent and non-existent users - SQL injection and Unauthenticated Arbitrary File Read Some Other minor bug fixes https://ocsinventory-ng.org/?lang=fr/

Change Log

References


[ 1 ] Bug #502250 - CVE-2009-1769 OCS Inventory NG: Authentication result varies for existent and non-existent users https://bugzilla.redhat.com/show_bug.cgi?id=502250

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update ocsinventory' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ocsinventory
Product: Fedora 9
Version: 1.02.1
Release: 1.fc9
Summary: Open Computer and Software Inventory Next Generation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here