MGASA-2015-0001
Dashboard / Vulnerabilities / MGASA-2015-0001
Summary: Updated openvas-manager packages fix security vulnerability
Details: Updated openvas-manager packages fixes security vulnerability: It has been identified that OpenVAS Manager before 4.0.6 is vulnerable to sql injections due to a improper handling of the timezone parameter in modify_schedule OMP command. It has been identified that this vulnerability may allow read-access via sql for authorized user account which have permission to modify schedule objects (CVE-2014-9220).
References: https://advisories.mageia.org/MGASA-2015-0001.html, https://bugs.mageia.org/show_bug.cgi?id=14718, http://www.openvas.org/OVSA20141128.html, http://openwall.com/lists/oss-security/2014/12/03/1
Affected packages
Package
Name: openvas-manager
Purl: pkg:rpm/mageia/openvas-manager?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
