Vulnerabilities > CVE-2010-3583 - Unspecified vulnerability in Oracle VM 2.2.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN oracle
nessus
Summary
Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a third party researcher that this is related to the exposure of multiple unspecified functions through XML-RPC that allow execution of arbitrary OS commands.
Nessus
NASL family | OracleVM Local Security Checks |
NASL id | ORACLEVM_OVMSA-2010-0015.NASL |
description | The remote OracleVM system is missing necessary patches to address critical security updates : - Update changelog, fill CVE number. - Fix config-file access mode issue. - Fix file access vulnerability [orabug 10142417] (CVE-2010-3582) - Fix local privilege escalation [orabug 10142476] (CVE-2010-3584) - Fix ovs agent command injection [orabug 10146644] (CVE-2010-3585) - Fix validate master ip command injection [orabug 10142448] (CVE-2010-3583) - Add excutable mode to utils/upgrade.py. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 68878 |
published | 2013-07-15 |
reporter | This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/68878 |
title | OracleVM 2.2 : ovs-agent (OVMSA-2010-0015) |
code |
|
References
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
- http://www.securityfocus.com/archive/1/514613/100/0/threaded
- http://www.securityfocus.com/archive/1/514613/100/0/threaded
- http://www.us-cert.gov/cas/techalerts/TA10-287A.html
- http://www.us-cert.gov/cas/techalerts/TA10-287A.html