Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Gentoo: 200305-10 Moderate Risk of Remote Exploit via Nessus Tool

gentoo
Calendar Grey May 27, 2003
Dist Gentoo Esm H88
Gentoo Linux Security Announcement highlights scripting flaws in Nessus that may lead to remote exploits. Upgrade recommended.
There exists some vulnerabilities in NASL scripting engine.

Summary


GENTOO LINUX SECURITY ANNOUNCEMENT 200305-10


- - From advisory:
"There exists some vulnerabilities in NASL scripting engine. To exploit these flaws, an attacker would need to have a valid Nessus account as well as the ability to upload arbitrary Nessus plugins in the Nessus server (this option is disabled by default) or he/she would need to trick a user somehow into running a specially crafted nasl script."
Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=105369506714849&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running net-analyzer/nessus upgrade to nessus-2.0.6a as follows
emerge sync emerge nessus emerge clean
aliz@gentoo.org - GnuPG key is available at

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

PACKAGE : nessus
SUMMARY : problems in scripting engine
DATE : 2003-05-27 09:15 UTC
EXPLOIT : remote
VERSIONS AFFECTED : =nessus-2.0.6a
CVE :

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here