All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
About Hackers
Analysis
News
Glossary
Weblog



 
Virus Encyclopedia
Virus Encyclopedia

Learn about worms, viruses, Trojans and more in our Virus Encyclopedia.

About Spam
About Spam

Read about spam and spammers in our About Spam section.

 

  Home / Hackers / About Hackers / Software Vulnerabilities / Examples and Descriptions / SA38497

Fedora update for ocsinventory

Secunia ID

SA38497

Release Date

09 Feb 2010

Criticality

Less Critical

Solution Status

Vendor Patch

Where

From remote

Impact
Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.


Manipulation of data

This includes vulnerabilities where a user or a remote attacker can manipulate local data on a system, but not necessarily be able to gain escalated privileges or system access.

The most frequent type of vulnerabilities with this impact are SQL-injection vulnerabilities, where a malicious user or person can manipulate SQL queries.


Description

Fedora has issued an update for ocsinventory. This fixes multiple vulnerabilities, which can be exploited by malicious users to conduct SQL injection attacks.

For more information see vulnerability #2 in:
SA38311

Solution

Apply updated packages via the yum utility ("yum update ocsinventory").

Original Advisory

FEDORA-2010-1535:
https://admin.fedoraproject.org/updates/F12/FEDORA-2010-1535

FEDORA-2010-1540:
https://admin.fedoraproject.org/updates/F11/FEDORA-2010-1540




 

Copyright © 1996 - 2010
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com