Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 21529 - net-analyzer/nessus
Summary: net-analyzer/nessus
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: Highest critical (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-05-23 04:30 UTC by Daniel Ahlberg (RETIRED)
Modified: 2003-05-27 05:15 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Ahlberg (RETIRED) gentoo-dev 2003-05-23 04:30:44 UTC
Nessus 2.0.6 has been released. It fixes a potential security vulnerability in 
libnasl as well as some other buglets. 
 
There are some flaws in libnasl which might let a script break out of its 
sandboxed environment and execute arbitrary commands on the nessusd host. 
To exploit these flaws, an attacker would need to have a valid Nessus account 
as well as the ability to upload arbitrary Nessus plugins in the Nessus 
server (this option is disabled by default). 
 
Not that these issues can NOT be exploited by a tested host to crash nessusd 
remotely. 
 
. Solution 
 
Upgrade to Nessus 2.0.6 available at : 
        http://ftp.nessus.org/nessus/nessus-2.0.6/ 
        ftp://ftp.nessus.org/pub/nessus/nessus-2.0.6/ 
 
. Workaround 
 
Make sure the option 'plugins_upload' is set to 'no' in nessusd.conf 
 
. Thanks 
 
"Sir Mordred" <mordred@s-mail.com> discovered some ways to crash NASL scripts 
by sending bad parameters to insstr(), ftp_log_in(), and other functions. 
Upon investigation, we fixed similar issues in other nasl functions as well 
as in libnessus.
Comment 1 Patrick Kursawe (RETIRED) gentoo-dev 2003-05-23 07:21:33 UTC
Little correction: It's 2.0.6a - just compiling it to see if copying the ebuilds is good enough.
Comment 2 Patrick Kursawe (RETIRED) gentoo-dev 2003-05-23 07:44:16 UTC
Compiled fine, survived one test run. Committing as ~arch.
Comment 3 Daniel Ahlberg (RETIRED) gentoo-dev 2003-05-27 05:15:15 UTC
glsa sent