OracleVM 2.2:内核 (OVMSA-2013-0039)

high Nessus 插件 ID 79507

简介

远程 OracleVM 主机缺少一个或多个安全更新。

描述

远程 OracleVM 系统缺少解决关键安全更新的必要补丁:有关详细信息,请参阅 Oracle VM 安全公告 OVMSA-2013-0039。

解决方案

更新受影响的数据包。

另见

https://oss.oracle.com/pipermail/oraclevm-errata/2013-May/000153.html

插件详情

严重性: High

ID: 79507

文件名: oraclevm_OVMSA-2013-0039.nasl

版本: 1.27

类型: local

发布时间: 2014/11/26

最近更新时间: 2021/1/4

风险信息

VPR

风险因素: Critical

分数: 9.7

CVSS v2

风险因素: Critical

基本分数: 10

时间分数: 8.7

矢量: AV:N/AC:L/Au:N/C:C/I:C/A:C

时间矢量: E:H/RL:OF/RC:C

CVSS v3

风险因素: High

基本分数: 8.8

时间分数: 8.4

矢量: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

时间矢量: E:H/RL:O/RC:C

漏洞信息

CPE: p-cpe:/a:oracle:vm:kernel, p-cpe:/a:oracle:vm:kernel-PAE, p-cpe:/a:oracle:vm:kernel-PAE-devel, p-cpe:/a:oracle:vm:kernel-devel, p-cpe:/a:oracle:vm:kernel-ovs, p-cpe:/a:oracle:vm:kernel-ovs-devel, cpe:/o:oracle:vm_server:2.2

必需的 KB 项: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

可利用: true

易利用性: Exploits are available

补丁发布日期: 2013/5/23

漏洞发布日期: 2006/12/14

可利用的方式

CANVAS (CANVAS)

Core Impact

Metasploit (Linux Kernel Sendpage Local Privilege Escalation)

参考资料信息

CVE: CVE-2006-6304, CVE-2007-4567, CVE-2009-0745, CVE-2009-0746, CVE-2009-0747, CVE-2009-0748, CVE-2009-1388, CVE-2009-1389, CVE-2009-1895, CVE-2009-2406, CVE-2009-2407, CVE-2009-2692, CVE-2009-2847, CVE-2009-2848, CVE-2009-2908, CVE-2009-3080, CVE-2009-3286, CVE-2009-3547, CVE-2009-3612, CVE-2009-3620, CVE-2009-3621, CVE-2009-3726, CVE-2009-4020, CVE-2009-4021, CVE-2009-4067, CVE-2009-4138, CVE-2009-4141, CVE-2009-4307, CVE-2009-4308, CVE-2009-4536, CVE-2009-4537, CVE-2009-4538, CVE-2010-0007, CVE-2010-0415, CVE-2010-0437, CVE-2010-0622, CVE-2010-0727, CVE-2010-1083, CVE-2010-1084, CVE-2010-1086, CVE-2010-1087, CVE-2010-1088, CVE-2010-1173, CVE-2010-1188, CVE-2010-1436, CVE-2010-1437, CVE-2010-1641, CVE-2010-2226, CVE-2010-2240, CVE-2010-2248, CVE-2010-2521, CVE-2010-2798, CVE-2010-2942, CVE-2010-2963, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086, CVE-2010-3296, CVE-2010-3432, CVE-2010-3442, CVE-2010-3477, CVE-2010-3858, CVE-2010-3859, CVE-2010-3876, CVE-2010-3877, CVE-2010-4073, CVE-2010-4080, CVE-2010-4081, CVE-2010-4083, CVE-2010-4157, CVE-2010-4158, CVE-2010-4242, CVE-2010-4248, CVE-2010-4249, CVE-2010-4258, CVE-2010-4346, CVE-2010-4649, CVE-2010-4655, CVE-2011-0521, CVE-2011-0726, CVE-2011-1010, CVE-2011-1020, CVE-2011-1044, CVE-2011-1078, CVE-2011-1079, CVE-2011-1080, CVE-2011-1083, CVE-2011-1090, CVE-2011-1093, CVE-2011-1160, CVE-2011-1162, CVE-2011-1163, CVE-2011-1182, CVE-2011-1573, CVE-2011-1577, CVE-2011-1585, CVE-2011-1745, CVE-2011-1746, CVE-2011-1776, CVE-2011-1833, CVE-2011-2022, CVE-2011-2203, CVE-2011-2213, CVE-2011-2482, CVE-2011-2484, CVE-2011-2491, CVE-2011-2496, CVE-2011-2525, CVE-2011-3191, CVE-2011-3637, CVE-2011-3638, CVE-2011-4077, CVE-2011-4086, CVE-2011-4110, CVE-2011-4127, CVE-2011-4324, CVE-2011-4330, CVE-2011-4348, CVE-2012-1583, CVE-2012-2136

BID: 35281, 35647, 35850, 35851, 35930, 36038, 36472, 36639, 36723, 36824, 36827, 36901, 36936, 37068, 37069, 37339, 37519, 37521, 37523, 37762, 37806, 38144, 38165, 38185, 38479, 38898, 39016, 39042, 39044, 39101, 39569, 39715, 39719, 39794, 40356, 40920, 42124, 42242, 42249, 42505, 42529, 43022, 43221, 43353, 43480, 43787, 43809, 44242, 44301, 44354, 44630, 44648, 44754, 44758, 45014, 45028, 45037, 45058, 45063, 45073, 45159, 45323, 45972, 45986, 46073, 46488, 46492, 46567, 46616, 46630, 46766, 46793, 46866, 46878, 47003, 47308, 47321, 47343, 47381, 47534, 47535, 47791, 47796, 47843, 48236, 48333, 48383, 48641, 48687, 49108, 49141, 49295, 49373, 50322, 50370, 50750, 50755, 50764, 50798, 51176, 51361, 51363, 51945, 53139, 53721

CWE: 16, 20, 119, 189, 200, 264, 362, 399