Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 821493 (CVE-2021-20135) - <net-analyzer/nessus-bin-10.0.1: privilege escalation to agents (CVE-2021-20135)
Summary: <net-analyzer/nessus-bin-10.0.1: privilege escalation to agents (CVE-2021-20135)
Status: RESOLVED FIXED
Alias: CVE-2021-20135
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial
Assignee: Gentoo Security
URL: https://www.tenable.com/security/tns-...
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-11-03 16:23 UTC by John Helmert III
Modified: 2021-11-18 22:14 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-11-03 16:23:53 UTC
CVE-2021-20135:

Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. Tenable has included a fix for this issue in Nessus 10.0.0. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus).

Please bump.
Comment 1 Rick Farina (Zero_Chaos) gentoo-dev 2021-11-18 22:04:15 UTC
10.0.1 added to the tree
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-11-18 22:14:07 UTC
(In reply to Rick Farina (Zero_Chaos) from comment #1)
> 10.0.1 added to the tree

If you know a release is a security release, please look for a security bug so you can properly tag your commits. If you don't find a security bug, please file one.

Tree is clean, all done.