PT-2008-6965 · Opensuse · Openwsman-Debugsource+9

Publicado

1970-01-01

·

Atualizado

2011-03-08

·

CVE-2008-2233

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions openwsman versions 1.2.0 through 2.0.0 openwsman-client (affected versions not specified) openwsman-server (affected versions not specified) openwsman-devel (affected versions not specified) libwsman1 (affected versions not specified) libwsman-devel (affected versions not specified) openwsman-debugsource (affected versions not specified) openwsman-ruby (affected versions not specified) openwsman-python (affected versions not specified) openwsman-debuginfo (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the openwsman package of the openSUSE operating system, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The client in Openwsman, in unknown configurations, allows remote Openwsman servers to replay SSL sessions via unspecified vectors.
Recommendations For openwsman versions 1.2.0 through 2.0.0, update to a version outside of this range to mitigate the risk. For openwsman-client, consider disabling the client functionality until a patch is available. For openwsman-server, restrict access to the server to minimize the risk of exploitation. For openwsman-devel, libwsman1, libwsman-devel, openwsman-debugsource, openwsman-ruby, openwsman-python, and openwsman-debuginfo, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-05024
BDU:2015-05025
BDU:2015-05026
BDU:2015-05027
BDU:2015-05028
BDU:2015-05029
BDU:2015-05030
BDU:2015-05031
BDU:2015-05032
BDU:2015-05033
CVE-2008-2233

Produtos afetados

Libwsman-Devel
Libwsman1
Openwsman
Openwsman-Client
Openswan-Debuginfo
Openwsman-Debugsource
Openwsman-Devel
Openwsman-Python
Openwsman-Ruby
Openwsman-Server