Summary: | <net-analyzer/openvas-manager-4.0.6/5.0.7 SQL injection (CVE-2014-9220) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Justin Lecher (RETIRED) <jlec> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | hanno |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | ~3 [noglsa] | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- |
Description
Justin Lecher (RETIRED)
![]() +*openvas-manager-6.0_beta4 (01 Dec 2014) +*openvas-manager-5.0.7 (01 Dec 2014) + + 01 Dec 2014; Justin Lecher <jlec@gentoo.org> -openvas-manager-4.0.4.ebuild, + -openvas-manager-5.0.4-r2.ebuild, -openvas-manager-5.0.5.ebuild, + +openvas-manager-5.0.7.ebuild, +openvas-manager-6.0_beta4.ebuild: + Version Bump; drop old vulnerable versions, #531094 + Thank you for the report, fix and cleanup. Non-stable package, closing noglsa CVE-2014-9220 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9220): SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command. |