MGASA-2013-0305
Dashboard / Vulnerabilities / MGASA-2013-0305
Summary: Updated nmap package fixes CVE-2013-4885
Details: Updated nmap packages fix security vulnerability: It is possible to write arbitrary files to a remote system, through a specially crafted server response for NMAP http-domino-enum-passwords.nse script from nmap before 6.40 (CVE-2013-4885).
References: https://advisories.mageia.org/MGASA-2013-0305.html, http://packetstormsecurity.com/files/122719/TWSL2013-025.txt, https://lists.fedoraproject.org/pipermail/package-announce/2013-August/114768.html, https://bugs.mageia.org/show_bug.cgi?id=11090
Affected packages
Package
Name: nmap
Purl: pkg:rpm/mageia/nmap?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -6.25-3.1.mga3
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
