Executive Summary
Summary | |
---|---|
Title | file security and bug fix update |
Informations | |||
---|---|---|---|
Name | RHSA-2014:1606 | First vendor Publication | 2014-10-14 |
Vendor | RedHat | Last vendor Modification | 2014-10-14 |
Severity (Vendor) | Moderate | Revision | 02 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: Updated file packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: The "file" command is used to identify a particular file according to the type of data contained in the file. The command can identify various file types, including ELF binaries, system libraries, RPM packages, and different graphics formats. Multiple denial of service flaws were found in the way file parsed certain Composite Document Format (CDF) files. A remote attacker could use either of these flaws to crash file, or an application using file, via a specially crafted CDF file. (CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, CVE-2014-3480, CVE-2012-1571) Two denial of service flaws were found in the way file handled indirect and search rules. A remote attacker could use either of these flaws to cause file, or an application using file, to crash or consume an excessive amount of CPU. (CVE-2014-1943, CVE-2014-2270) This update also fixes the following bugs: * Previously, the output of the "file" command contained redundant white spaces. With this update, the new STRING_TRIM flag has been introduced to remove the unnecessary white spaces. (BZ#664513) * Due to a bug, the "file" command could incorrectly identify an XML document as a LaTex document. The underlying source code has been modified to fix this bug and the command now works as expected. (BZ#849621) * Previously, the "file" command could not recognize .JPG files and incorrectly labeled them as "Minix filesystem". This bug has been fixed and the command now properly detects .JPG files. (BZ#873997) * Under certain circumstances, the "file" command incorrectly detected NETpbm files as "x86 boot sector". This update applies a patch to fix this bug and the command now detects NETpbm files as expected. (BZ#884396) * Previously, the "file" command incorrectly identified ASCII text files as a .PIC image file. With this update, a patch has been provided to address this bug and the command now correctly recognizes ASCII text files. (BZ#980941) * On 32-bit PowerPC systems, the "from" field was missing from the output of the "file" command. The underlying source code has been modified to fix this bug and "file" output now contains the "from" field as expected. (BZ#1037279) * The "file" command incorrectly detected text files as "RRDTool DB version ool - Round Robin Database Tool". This update applies a patch to fix this bug and the command now correctly detects text files. (BZ#1064463) * Previously, the "file" command supported only version 1 and 2 of the QCOW format. As a consequence, file was unable to detect a "qcow2 compat=1.1" file created on Red Hat Enterprise Linux 7. With this update, support for QCOW version 3 has been added so that the command now detects such files as expected. (BZ#1067771) All file users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 664513 - too many spaces ... 805197 - CVE-2012-1571 file: out of bounds read in CDF parser 849621 - file is coming back with 'LaTeX document text' instead of 'XML document text' 873997 - file thinks the attached jpg is "Minix filesystem, V2, 50968 zones" 884396 - file detects netpbm files as x86 boot sector type sometimes 980941 - file reported wrong file type (reported .PIC image file instead of ASCII text file) 1064463 - text file detected as 'RRDTool DB version ool - Round Robin Database Tool' 1065836 - CVE-2014-1943 file: unrestricted recursion in handling of indirect type rules 1067771 - file unable to detect qcow2 compat=1.1 img created by RHEL7 1072220 - CVE-2014-2270 file: out-of-bounds access in search rules with offsets from input file 1098155 - CVE-2014-0238 file: CDF property info parsing nelements infinite loop 1098193 - CVE-2014-0237 file: cdf_unpack_summary_info() excessive looping DoS 1104858 - CVE-2014-3480 file: cdf_count_chain insufficient boundary check 1104869 - CVE-2014-3479 file: cdf_check_stream_offset insufficient boundary check |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2014-1606.html |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
60 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
20 % | CWE-755 | Improper Handling of Exceptional Conditions |
20 % | CWE-399 | Resource Management Errors |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:15392 | |||
Oval ID: | oval:org.mitre.oval:def:15392 | ||
Title: | DSA-2422-1 file -- missing bounds checks | ||
Description: | The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File format, leading to crashes. Note that after this update, file may return different detection results for CDF files. The new detections are believed to be more accurate. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2422-1 CVE-2012-1571 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | file |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:23670 | |||
Oval ID: | oval:org.mitre.oval:def:23670 | ||
Title: | DSA-2861-1 file - denial of service | ||
Description: | It was discovered that file, a file type classification tool, contains a flaw in the handling of <q>indirect</q> magic rules in the libmagic library, which leads to an infinite recursion when trying to determine the file type of certain files. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2861-1 CVE-2014-1943 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/Linux 7 Debian GNU/kFreeBSD 6.0 Debian GNU/kFreeBSD 7 | Product(s): | file |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:23706 | |||
Oval ID: | oval:org.mitre.oval:def:23706 | ||
Title: | DSA-2868-1 php5 - denial of service | ||
Description: | It was discovered that file, a file type classification tool, contains a flaw in the handling of <q>indirect</q> magic rules in the libmagic library, which leads to an infinite recursion when trying to determine the file type of certain files. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2868-1 CVE-2014-1943 | Version: | 5 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/Linux 7 Debian GNU/kFreeBSD 6.0 Debian GNU/kFreeBSD 7 | Product(s): | php5 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:24044 | |||
Oval ID: | oval:org.mitre.oval:def:24044 | ||
Title: | USN-2123-1 -- file vulnerabilities | ||
Description: | File could be made to crash if it processed a specially crafted file. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2123-1 CVE-2012-1571 CVE-2014-1943 | Version: | 5 |
Platform(s): | Ubuntu 13.10 Ubuntu 12.10 Ubuntu 12.04 Ubuntu 10.04 | Product(s): | file |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:24248 | |||
Oval ID: | oval:org.mitre.oval:def:24248 | ||
Title: | USN-2163-1 -- php5 vulnerability | ||
Description: | PHP could be made to crash if it processed a specially crafted file. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2163-1 CVE-2014-2270 | Version: | 5 |
Platform(s): | Ubuntu 13.10 Ubuntu 12.10 Ubuntu 12.04 Ubuntu 10.04 | Product(s): | php5 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:24326 | |||
Oval ID: | oval:org.mitre.oval:def:24326 | ||
Title: | USN-2162-1 -- file vulnerability | ||
Description: | File could be made to crash if it processed a specially crafted file. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2162-1 CVE-2014-2270 | Version: | 5 |
Platform(s): | Ubuntu 13.10 Ubuntu 12.10 Ubuntu 12.04 Ubuntu 10.04 | Product(s): | file |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:24786 | |||
Oval ID: | oval:org.mitre.oval:def:24786 | ||
Title: | DSA-2943-1 php5 - security update | ||
Description: | Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2943-1 CVE-2014-0185 CVE-2014-0237 CVE-2014-0238 CVE-2014-2270 | Version: | 3 |
Platform(s): | Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | php5 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:25162 | |||
Oval ID: | oval:org.mitre.oval:def:25162 | ||
Title: | SUSE-SU-2014:0670-1 -- Security update for file | ||
Description: | The command line tool file(1) and its library libmagic have been updated to fix the following issues: * file(1) crashed when parsing some PE executables. (CVE-2014-2270, bnc#866750) * file(1) did not set return code on non-existing files. (bnc#863450) Security Issue reference: * CVE-2014-2270 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2270> | ||
Family: | unix | Class: | patch |
Reference(s): | SUSE-SU-2014:0670-1 CVE-2014-2270 | Version: | 3 |
Platform(s): | SUSE Linux Enterprise Server 11 SUSE Linux Enterprise Desktop 11 | Product(s): | file |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:27101 | |||
Oval ID: | oval:org.mitre.oval:def:27101 | ||
Title: | RHSA-2014:1606: file security and bug fix update (Moderate) | ||
Description: | The "file" command is used to identify a particular file according to the type of data contained in the file. The command can identify various file types, including ELF binaries, system libraries, RPM packages, and different graphics formats. Multiple denial of service flaws were found in the way file parsed certain Composite Document Format (CDF) files. A remote attacker could use either of these flaws to crash file, or an application using file, via a specially crafted CDF file. (CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, CVE-2014-3480, CVE-2012-1571) Two denial of service flaws were found in the way file handled indirect and search rules. A remote attacker could use either of these flaws to cause file, or an application using file, to crash or consume an excessive amount of CPU. (CVE-2014-1943, CVE-2014-2270) This update also fixes the following bugs: * Previously, the output of the "file" command contained redundant white spaces. With this update, the new STRING_TRIM flag has been introduced to remove the unnecessary white spaces. (BZ#664513) * Due to a bug, the "file" command could incorrectly identify an XML document as a LaTex document. The underlying source code has been modified to fix this bug and the command now works as expected. (BZ#849621) * Previously, the "file" command could not recognize .JPG files and incorrectly labeled them as "Minix filesystem". This bug has been fixed and the command now properly detects .JPG files. (BZ#873997) * Under certain circumstances, the "file" command incorrectly detected NETpbm files as "x86 boot sector". This update applies a patch to fix this bug and the command now detects NETpbm files as expected. (BZ#884396) * Previously, the "file" command incorrectly identified ASCII text files as a .PIC image file. With this update, a patch has been provided to address this bug and the command now correctly recognizes ASCII text files. (BZ#980941) * On 32-bit PowerPC systems, the "from" field was missing from the output of the "file" command. The underlying source code has been modified to fix this bug and "file" output now contains the "from" field as expected. (BZ#1037279) * The "file" command incorrectly detected text files as "RRDTool DB version ool - Round Robin Database Tool". This update applies a patch to fix this bug and the command now correctly detects text files. (BZ#1064463) * Previously, the "file" command supported only version 1 and 2 of the QCOW format. As a consequence, file was unable to detect a "qcow2 compat=1.1" file created on Red Hat Enterprise Linux 7. With this update, support for QCOW version 3 has been added so that the command now detects such files as expected. (BZ#1067771) All file users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2014:1606-01 CVE-2012-1571 CVE-2014-0237 CVE-2014-0238 CVE-2014-1943 CVE-2014-2270 CVE-2014-3479 CVE-2014-3480 CESA-2014:1606 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 6 CentOS Linux 6 | Product(s): | file |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:27121 | |||
Oval ID: | oval:org.mitre.oval:def:27121 | ||
Title: | ELSA-2014-1606 -- file security and bug fix update | ||
Description: | [5.04-21] - fix typographical error in changelog [5.04-20] - fix #1037279 - better patch for the bug from previous release [5.04-19] - fix #1037279 - display 'from' field on 32bit ppc core [5.04-18] - fix #664513 - trim white-spaces during ISO9660 detection [5.04-17] - fix CVE-2014-3479 (cdf_check_stream_offset boundary check) - fix CVE-2014-3480 (cdf_count_chain insufficient boundary check) - fix CVE-2014-0237 (cdf_unpack_summary_info() excessive looping DoS) - fix CVE-2014-0238 (CDF property info parsing nelements infinite loop) - fix CVE-2014-2270 (out-of-bounds access in search rules with offsets) - fix CVE-2014-1943 (unrestricted recursion in handling of indirect type rules) - fix CVE-2012-1571 (out of bounds read in CDF parser) [5.04-16] - fix #873997 - improve Minix detection pattern to fix false positives - fix #884396 - improve PBM pattern to fix misdetection with x86 boot sector - fix #980941 - improve Bio-Rad pattern to fix false positives - fix #849621 - tweak strength of XML, Latex and Python patterns to execute them in the proper order - fix #1067771 - detect qcow version 3 images - fix #1064463 - treat RRDTool files as binary files | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2014-1606 CVE-2014-0237 CVE-2014-0238 CVE-2014-3479 CVE-2014-3480 CVE-2012-1571 CVE-2014-1943 CVE-2014-2270 | Version: | 4 |
Platform(s): | Oracle Linux 6 | Product(s): | file file-devel file-libs file-static python-magic |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:29238 | |||
Oval ID: | oval:org.mitre.oval:def:29238 | ||
Title: | DSA-2422-2 -- file -- missing bounds checks | ||
Description: | The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2422-2 CVE-2012-1571 | Version: | 3 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | file |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-09-26 | Name : Gentoo Security Advisory GLSA 201209-14 (file) File : nvt/glsa_201209_14.nasl |
2012-08-03 | Name : Mandriva Update for file MDVSA-2012:035 (file) File : nvt/gb_mandriva_MDVSA_2012_035.nasl |
2012-05-31 | Name : Debian Security Advisory DSA 2422-2 (file) File : nvt/deb_2422_2.nasl |
2012-03-12 | Name : Debian Security Advisory DSA 2422-1 (file) File : nvt/deb_2422_1.nasl |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2014-07-03 | IAVM : 2014-B-0086 - Multiple Vulnerabilities in PHP Severity : Category I - VMSKEY : V0052897 |
Snort® IPS/IDS
Date | Description |
---|---|
2016-03-29 | PHP libmagic PE out of bounds memory access attempt RuleID : 38347 - Revision : 1 - Type : FILE-EXECUTABLE |
2015-10-20 | PHP CDF file handling infinite loop dos attempt RuleID : 36059 - Revision : 3 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-08-29 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2016-1638-1.nasl - Type : ACT_GATHER_INFO |
2016-08-12 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_70140f20600711e6a6c314dae9d210b8.nasl - Type : ACT_GATHER_INFO |
2016-05-16 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2016-0050.nasl - Type : ACT_GATHER_INFO |
2016-01-22 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL16875.nasl - Type : ACT_GATHER_INFO |
2015-12-22 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20151119_file_on_SL7_x.nasl - Type : ACT_GATHER_INFO |
2015-12-02 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-2155.nasl - Type : ACT_GATHER_INFO |
2015-11-24 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-2155.nasl - Type : ACT_GATHER_INFO |
2015-11-20 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-2155.nasl - Type : ACT_GATHER_INFO |
2015-09-18 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL16954.nasl - Type : ACT_GATHER_INFO |
2015-04-10 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_10_10_3.nasl - Type : ACT_GATHER_INFO |
2015-04-10 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_SecUpd2015-004.nasl - Type : ACT_GATHER_INFO |
2015-03-30 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-080.nasl - Type : ACT_GATHER_INFO |
2015-03-26 | Name : The remote Debian host is missing a security update. File : debian_DLA-145.nasl - Type : ACT_GATHER_INFO |
2015-03-26 | Name : The remote Debian host is missing a security update. File : debian_DLA-18.nasl - Type : ACT_GATHER_INFO |
2015-03-26 | Name : The remote Debian host is missing a security update. File : debian_DLA-27.nasl - Type : ACT_GATHER_INFO |
2015-03-24 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201503-08.nasl - Type : ACT_GATHER_INFO |
2015-01-19 | Name : The remote Solaris system is missing a security patch for third-party software. File : solaris11_php_20140522.nasl - Type : ACT_GATHER_INFO |
2014-11-12 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1606.nasl - Type : ACT_GATHER_INFO |
2014-11-04 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20141014_file_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2014-10-17 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1606.nasl - Type : ACT_GATHER_INFO |
2014-10-14 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1606.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-361.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-362.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-367.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-372.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-382.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-393.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-398.nasl - Type : ACT_GATHER_INFO |
2014-10-12 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-415.nasl - Type : ACT_GATHER_INFO |
2014-10-01 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1326.nasl - Type : ACT_GATHER_INFO |
2014-10-01 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1327.nasl - Type : ACT_GATHER_INFO |
2014-10-01 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1326.nasl - Type : ACT_GATHER_INFO |
2014-10-01 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1327.nasl - Type : ACT_GATHER_INFO |
2014-10-01 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1327.nasl - Type : ACT_GATHER_INFO |
2014-09-30 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1326.nasl - Type : ACT_GATHER_INFO |
2014-09-18 | Name : The remote host is missing a Mac OS X update that fixes multiple vulnerabilit... File : macosx_10_9_5.nasl - Type : ACT_GATHER_INFO |
2014-09-12 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-172.nasl - Type : ACT_GATHER_INFO |
2014-09-10 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3021.nasl - Type : ACT_GATHER_INFO |
2014-09-03 | Name : The remote Fedora host is missing a security update. File : fedora_2014-9679.nasl - Type : ACT_GATHER_INFO |
2014-09-03 | Name : The remote Fedora host is missing a security update. File : fedora_2014-9684.nasl - Type : ACT_GATHER_INFO |
2014-08-30 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201408-11.nasl - Type : ACT_GATHER_INFO |
2014-08-20 | Name : The remote web server uses a version of PHP that is affected by multiple vuln... File : php_5_3_29.nasl - Type : ACT_GATHER_INFO |
2014-08-19 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_d2a892b9260511e49da000a0986f28c4.nasl - Type : ACT_GATHER_INFO |
2014-08-07 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1012.nasl - Type : ACT_GATHER_INFO |
2014-08-07 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2014-1013.nasl - Type : ACT_GATHER_INFO |
2014-08-07 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1012.nasl - Type : ACT_GATHER_INFO |
2014-08-07 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2014-1013.nasl - Type : ACT_GATHER_INFO |
2014-08-07 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20140806_php53_and_php_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2014-08-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1012.nasl - Type : ACT_GATHER_INFO |
2014-08-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1013.nasl - Type : ACT_GATHER_INFO |
2014-07-30 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_apache2-mod_php53-140720.nasl - Type : ACT_GATHER_INFO |
2014-07-24 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-464.nasl - Type : ACT_GATHER_INFO |
2014-07-16 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2278-1.nasl - Type : ACT_GATHER_INFO |
2014-07-14 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2014-192-01.nasl - Type : ACT_GATHER_INFO |
2014-07-10 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-130.nasl - Type : ACT_GATHER_INFO |
2014-07-10 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-131.nasl - Type : ACT_GATHER_INFO |
2014-07-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2276-1.nasl - Type : ACT_GATHER_INFO |
2014-07-09 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2974.nasl - Type : ACT_GATHER_INFO |
2014-07-08 | Name : The remote Fedora host is missing a security update. File : fedora_2014-7782.nasl - Type : ACT_GATHER_INFO |
2014-07-06 | Name : The remote Fedora host is missing a security update. File : fedora_2014-7992.nasl - Type : ACT_GATHER_INFO |
2014-07-04 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_apache2-mod_php53-140627.nasl - Type : ACT_GATHER_INFO |
2014-07-01 | Name : The remote Fedora host is missing a security update. File : fedora_2014-7765.nasl - Type : ACT_GATHER_INFO |
2014-06-27 | Name : The remote web server is running a version of PHP that is affected by multipl... File : php_5_4_30.nasl - Type : ACT_GATHER_INFO |
2014-06-27 | Name : The remote web server is running a version of PHP that is affected by multipl... File : php_5_5_14.nasl - Type : ACT_GATHER_INFO |
2014-06-26 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2254-2.nasl - Type : ACT_GATHER_INFO |
2014-06-24 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2254-1.nasl - Type : ACT_GATHER_INFO |
2014-06-18 | Name : The remote Fedora host is missing one or more security updates. File : fedora_2014-6901.nasl - Type : ACT_GATHER_INFO |
2014-06-18 | Name : The remote Fedora host is missing one or more security updates. File : fedora_2014-6904.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2012-221.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-209.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-255.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2014-419.nasl - Type : ACT_GATHER_INFO |
2014-06-11 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-115.nasl - Type : ACT_GATHER_INFO |
2014-06-11 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-116.nasl - Type : ACT_GATHER_INFO |
2014-06-10 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2014-160-01.nasl - Type : ACT_GATHER_INFO |
2014-06-03 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2943.nasl - Type : ACT_GATHER_INFO |
2014-06-03 | Name : The remote web server uses a version of PHP that is affected by multiple vuln... File : php_5_4_29.nasl - Type : ACT_GATHER_INFO |
2014-06-03 | Name : The remote web server uses a version of PHP that is affected by multiple vuln... File : php_5_5_13.nasl - Type : ACT_GATHER_INFO |
2014-05-19 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_file-140331.nasl - Type : ACT_GATHER_INFO |
2014-04-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2162-1.nasl - Type : ACT_GATHER_INFO |
2014-04-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2163-1.nasl - Type : ACT_GATHER_INFO |
2014-03-31 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_7e61a839b71411e38195001966155bea.nasl - Type : ACT_GATHER_INFO |
2014-03-28 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-313.nasl - Type : ACT_GATHER_INFO |
2014-03-28 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-314.nasl - Type : ACT_GATHER_INFO |
2014-03-27 | Name : The remote Fedora host is missing a security update. File : fedora_2014-3589.nasl - Type : ACT_GATHER_INFO |
2014-03-18 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2014-304.nasl - Type : ACT_GATHER_INFO |
2014-03-17 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2014-074-01.nasl - Type : ACT_GATHER_INFO |
2014-03-17 | Name : The remote Fedora host is missing a security update. File : fedora_2014-3537.nasl - Type : ACT_GATHER_INFO |
2014-03-17 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-059.nasl - Type : ACT_GATHER_INFO |
2014-03-14 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201403-03.nasl - Type : ACT_GATHER_INFO |
2014-03-14 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2014-051.nasl - Type : ACT_GATHER_INFO |
2014-03-13 | Name : The remote Fedora host is missing a security update. File : fedora_2014-3606.nasl - Type : ACT_GATHER_INFO |
2014-03-12 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2873.nasl - Type : ACT_GATHER_INFO |
2014-03-10 | Name : The remote Fedora host is missing a security update. File : fedora_2014-3534.nasl - Type : ACT_GATHER_INFO |
2014-03-07 | Name : The remote web server uses a version of PHP that is potentially affected by m... File : php_5_4_26.nasl - Type : ACT_GATHER_INFO |
2014-03-07 | Name : The remote web server uses a version of PHP that is potentially affected by m... File : php_5_5_10.nasl - Type : ACT_GATHER_INFO |
2014-03-04 | Name : The remote Fedora host is missing a security update. File : fedora_2014-2876.nasl - Type : ACT_GATHER_INFO |
2014-03-04 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_815dbcf9a2d611e38088002590860428.nasl - Type : ACT_GATHER_INFO |
2014-03-04 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2126-1.nasl - Type : ACT_GATHER_INFO |
2014-03-03 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2868.nasl - Type : ACT_GATHER_INFO |
2014-02-27 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2123-1.nasl - Type : ACT_GATHER_INFO |
2014-02-24 | Name : The remote Fedora host is missing a security update. File : fedora_2014-2739.nasl - Type : ACT_GATHER_INFO |
2014-02-17 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2861.nasl - Type : ACT_GATHER_INFO |
2012-09-27 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201209-14.nasl - Type : ACT_GATHER_INFO |
2012-03-26 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2012-035.nasl - Type : ACT_GATHER_INFO |
2012-03-01 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2422.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-11-13 13:27:24 |
|
2014-10-18 13:26:19 |
|
2014-10-16 13:25:50 |
|
2014-10-14 09:22:22 |
|