Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 353191 (CVE-2011-0018) - net-analyzer/openvas: Command injection when processing OMP Requests (CVE-2011-0018)
Summary: net-analyzer/openvas: Command injection when processing OMP Requests (CVE-201...
Status: RESOLVED INVALID
Alias: CVE-2011-0018
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://www.openvas.org/OVSA20110118.html
Whiteboard: ~1
Keywords:
Depends on:
Blocks:
 
Reported: 2011-01-30 03:30 UTC by Yury German
Modified: 2012-01-12 14:42 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Yury German Gentoo Infrastructure gentoo-dev 2011-01-30 03:30:08 UTC
It has been identified that OpenVAS Manager is vulnerable to command injection due to insufficient validation of user supplied data when processing OMP requests. It has been identified that this vulnerability allows privilege escalation within the OpenVAS Manager but more complex injection may allow arbitrary code to be executed with the privileges of the OpenVAS Manager on vulnerable systems. CVE-2011-0018 has been assigned to this vulnerability.

The vulnerable code path is only accessible to authenticated users of OpenVAS Manager however it may also be triggered either directly or by using a cross-site request forgery based attack via the Greenbone Security Assistant web application.

** Current Status **

As of the 20th January 2011, the state of the vulnerabilities is believed to be as follows. A patch has been supplied by Greenbone Networks which it successfully resolves this vulnerability. New releases of both 1.0.x and 2.0.x have also been created which incorporate this patch. Note that the cross-site address forgery elements of this vulnerability have not yet been addressed in the Greenbone Security Assistant web application.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2011-06-24 00:34:40 UTC
CVE-2011-0018 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0018):
  The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3
  and 2.0.x through 2.0rc2 allows remote authenticated users to execute
  arbitrary commands via the (1) To or (2) From e-mail address in an OMP
  request to the Greenbone Security Assistant (GSA).
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-01-12 14:42:10 UTC
net-analyzer/openvas-manager-2.0.4 (pulled in by net-analyzer/openvas-4) is the only version ever in the tree and is not vulnerable. 

<net-analyzer/openvas-4 did not pull in net-analyzer/openvas-manager and so was also not vulnerable.