Summary
The latest update to the TrustKeeper scan engine that powers our Trustwave Vulnerability Management product (including both internal and external vulnerability scanning) is now available. Enjoy!
New Vulnerability Test Highlights
Some of the more interesting vulnerability tests we added recently are as follows:
Apache
- Apache HTTP Server mod_http2 Denial of Service Attack by Exhausting H2 Workers Vulnerability (httpd 2.4.41 Release) (CVE-2019-9517)
- Apache HTTP Server mod_http2 Memory Corruption on Early Pushes Vulnerability (httpd 2.4.41 Release) (CVE-2019-10081)
- Apache HTTP Server mod_http2 Read-After-Free in H2 Connection Shutdown Vulnerability (httpd 2.4.41 Release) (CVE-2019-10082)
- Apache HTTP Server mod_proxy Error Page Cross-Site Scripting Vulnerability (httpd 2.4.41 Release) (CVE-2019-10092)
- Apache HTTP Server mod_remoteip Stack Buffer Overflow and NULL Pointer Dereference Vulnerability (httpd 2.4.41 Release) (CVE-2019-10097)
- Apache HTTP Server mod_rewrite Potential Open Redirect Vulnerability (httpd 2.4.41 Release) (CVE-2019-10098)
- Apache Subversion svnserve get-deleted-rev Denial of Service Vulnerability (CVE-2018-11782)
- Apache Subversion svnserve Remote Unauthenticated Denial of Service Vulnerability (CVE-2019-0203)
Cisco
- Cisco ASA Smart Tunnel Vulnerabilities (cisco-sa-20190807-asa-multi, CSCvo78789) (CVE-2019-1945, CVE-2019-1944)
- Cisco ASA Web-Based Management Interface Privilege Escalation Vulnerability (cisco-sa-20190807-asa-privescala, CSCvp09150) (CVE-2019-1934)
ClamAV
- ClamAV NSIS bzip2 Decompression Out-of-Bounds Write Vulnerability (CVE-2019-12900)
cPanel
- cPanel Missing System Accounts Password Validation Vulnerability (CPANEL-9559) (CVE-2016-10791)
- cPanel Multiple Vulnerabilities (TSR-2017-0001) (CVE-2017-18482, CVE-2017-18481, CVE-2017-18480, CVE-2017-18479, CVE-2017-18478, CVE-2017-18477, CVE-2017-18476, CVE-2017-18475, CVE-2017-18474, CVE-2017-18473, CVE-2017-18472, CVE-2017-18471, CVE-2017-18470)
- cPanel Multiple Vulnerabilities (TSR-2019-0003) (CVE-2019-14398, CVE-2019-14397, CVE-2019-14396, CVE-2019-14395, CVE-2019-14394, CVE-2019-14393)
- cPanel Multiple Vulnerabilities (TSR-2019-0004) (CVE-2019-14392, CVE-2019-14391, CVE-2019-14390, CVE-2019-14389, CVE-2019-14388, CVE-2019-14387, CVE-2019-14386)
- cPanel Unreliable Suspend and Unsuspend Account Vulnerability (CPANEL-13941) (CVE-2017-18431)
FreeBSD
- FreeBSD bhyve Insufficient Validation of Guest-supplied Data Vulnerability (FreeBSD-SA-19:21.bhyve) (CVE-2019-5609)
- FreeBSD bsnmp Insufficient Message Length Validation Vulnerabilities (FreeBSD-SA-19:20.bsnmp) (CVE-2019-5610)
- FreeBSD bzip2 Multiple Vulnerabilities (FreeBSD-SA-19:18.bzip2) (CVE-2016-3189, CVE-2019-12900)
- FreeBSD IPv6 Denial of Service Vulnerability (FreeBSD-SA-19:22.mbuf) (CVE-2019-5611)
- FreeBSD Kernel Sound Module Memory Disclosure Vulnerability (FreeBSD-SA-19:23.midi) (CVE-2019-5612)
- FreeBSD MLDv2 Out-of-bounds Memory Access Vulnerability (FreeBSD-SA-19:19.mldv2) (CVE-2019-5608)
- FreeBSD mqueuefs Privilege EscalationVulnerability (FreeBSD-SA-19:24.mqueuefs) (CVE-2019-5603)
HP System Management
- HP System Management Homepage Denial of Service Vulnerability (HPSBMA02534) (CVE-2009-3555)
- HP System Management Homepage iprange Parameter Code Execution
- HP System Management Homepage Multiple Vulnerabilities (HPESBMU03753) (CVE-2016-8743, CVE-2017-12544, CVE-2017-12545, CVE-2017-12546, CVE-2017-12547, CVE-2017-12548, CVE-2017-12549, CVE-2017-12550, CVE-2017-12551, CVE-2017-12552, CVE-2017-12553)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMA02492 SSRT100079) (CVE-2008-1468, CVE-2008-4226, CVE-2008-5557, CVE-2008-5814, CVE-2009-1377, CVE-2009-1378, CVE-2009-1379, CVE-2009-1386, CVE-2009-1387, CVE-2010-1034)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMA02662 SSRT100409) (CVE-2010-1917, CVE-2010-2531, CVE-2010-2939, CVE-2010-2950, CVE-2010-3709, CVE-2010-4156, CVE-2011-1540, CVE-2011-1541, CVE-2010-4008)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU02764 SSRT100827) (CVE-2009-0037, CVE-2010-0734, CVE-2010-1452, CVE-2010-1623, CVE-2010-2068, CVE-2010-2791, CVE-2010-3436, CVE-2010-4409, CVE-2010-4645, CVE-2011-0014, CVE-2011-0195, CVE-2011-0419, CVE-2011-1148, CVE-2011-1153, CVE-2011-1464, CVE-2011-1467, CVE-2011-1468, CVE-2011-1470, CVE-2011-1471, CVE-2011-1928, CVE-2011-1938, CVE-2011-1945, CVE-2011-2192, CVE-2011-2202, CVE-2011-2483, CVE-2011-3182, CVE-2011-3189, CVE-2011-3192, CVE-2011-3207, CVE-2011-3210, CVE-2011-3267, CVE-2011-3268, CVE-2011-3348, CVE-2011-3368, CVE-2011-3639, CVE-2011-3846, CVE-2012-0135, CVE-2012-1993)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU02786 SSRT100877) (CVE-2011-1944, CVE-2011-2821, CVE-2011-2834, CVE-2011-3379, CVE-2011-3607, CVE-2011-4078, CVE-2011-4108, CVE-2011-4153, CVE-2011-4317, CVE-2011-4415, CVE-2011-4576, CVE-2011-4577, CVE-2011-4619, CVE-2011-4885, CVE-2012-0021, CVE-2012-0027, CVE-2012-0031, CVE-2012-0036, CVE-2012-0053, CVE-2012-0057, CVE-2012-0830, CVE-2012-1165, CVE-2012-1823, CVE-2012-2012, CVE-2012-2013, CVE-2012-2014, CVE-2012-2015, CVE-2012-2016)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU02900) (CVE-2011-3389, CVE-2012-0883, CVE-2012-2110, CVE-2012-2311, CVE-2012-2329, CVE-2012-2335, CVE-2012-2336, CVE-2012-5217, CVE-2013-2355, CVE-2013-2356, CVE-2013-2357, CVE-2013-2358, CVE-2013-2359, CVE-2013-2360, CVE-2013-2361, CVE-2013-2362, CVE-2013-2363, CVE-2013-2364, CVE-2013-4821)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU02917) (CVE-2013-3576)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU02947) (CVE-2013-4846, CVE-2013-6188)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU02998) (CVE-2013-4353, CVE-2013-6449, CVE-2013-6450, CVE-2014-0160)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU03051) (CVE-2010-5298, CVE-2014-0076, CVE-2014-0195, CVE-2014-0198, CVE-2014-0221, CVE-2014-0224, CVE-2014-3470)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU03112) (CVE-2013-4545, CVE-2013-6420, CVE-2013-6422, CVE-2013-6712, CVE-2014-2640, CVE-2014-2641, CVE-2014-2642)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU03380) (CVE-2014-0118, CVE-2014-0226, CVE-2014-0231, CVE-2014-3523, CVE-2014-3569, CVE-2014-3570, CVE-2014-3571, CVE-2014-3572, CVE-2014-8142, CVE-2014-8275, CVE-2014-9427, CVE-2014-9652, CVE-2014-9653, CVE-2014-9705, CVE-2015-0204, CVE-2015-0205, CVE-2015-0206, CVE-2015-0207, CVE-2015-0208, CVE-2015-0209, CVE-2015-0231, CVE-2015-0232, CVE-2015-0273, CVE-2015-0285, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0290, CVE-2015-0291, CVE-2015-0292, CVE-2015-0293, CVE-2015-1787, CVE-2015-2134, CVE-2015-2301, CVE-2015-2331, CVE-2015-2348, CVE-2015-2787)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU03422) (CVE-2014-0015, CVE-2014-0138, CVE-2014-0139, CVE-2014-2522, CVE-2014-2641, CVE-2014-3569, CVE-2014-3570, CVE-2014-3571, CVE-2014-3572, CVE-2014-8275, CVE-2015-0204, CVE-2015-0205, CVE-2015-0206, CVE-2015-0207, CVE-2015-0208, CVE-2015-0209, CVE-2015-0285, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0290, CVE-2015-0291, CVE-2015-0292, CVE-2015-0293, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-3143, CVE-2015-3145, CVE-2015-3148)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU03546) (CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-1793, CVE-2015-3143, CVE-2015-3145, CVE-2015-3148, CVE-2015-4000, CVE-2015-4024, CVE-2016-1993, CVE-2016-1994, CVE-2016-1995, CVE-2016-1996)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU03593) (CVE-2007-6750, CVE-2011-4969, CVE-2015-3194, CVE-2015-3195, CVE-2015-3237, CVE-2015-7995, CVE-2015-8035, CVE-2016-0705, CVE-2016-0799, CVE-2016-2015, CVE-2016-2842)
- HP System Management Homepage Multiple Vulnerabilities (HPSBMU03653) (CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109, CVE-2016-3739, CVE-2016-4070, CVE-2016-4071, CVE-2016-4072, CVE-2016-4342, CVE-2016-4343, CVE-2016-4393, CVE-2016-4394, CVE-2016-4395, CVE-2016-4396, CVE-2016-4537, CVE-2016-4538, CVE-2016-4539, CVE-2016-4540, CVE-2016-4541, CVE-2016-4542, CVE-2016-4543, CVE-2016-5385, CVE-2016-5387, CVE-2016-5388)
- HP System Management Homepage Remote Code Execution Vulnerability (HPSBMU03375) (CVE-2015-2133)
- HP System Management Homepage Remote Cross Site Scripting Vulnerability (HPSBMA02275 SSRT071445)
- HP System Management Homepage Remote Cross Site Scripting Vulnerability (HPSBMA02428 SSRT090048) (CVE-2009-1418)
- HP System Management Homepage Remote Cross Site Scripting Vulnerability (HPSBMA02504 SSRT090220) (CVE-2009-4185)
- HP System Management Homepage Remote Disclosure of Information Vulnerability (HPSBMU03260) (CVE-2014-3508, CVE-2014-3509, CVE-2014-3511, CVE-2014-3513, CVE-2014-3566, CVE-2014-3567, CVE-2014-3568, CVE-2014-5139)
MongoDB
- MongoDB - Unencrypted Communication Channel Accessibility
- MongoDB Concurrency and Authentication - Improper internal system privileges (SERVER-9983) (CVE-2013-4650)
- MongoDB JS Engine - V8 C++ bindings Remote Memory Corruption Vulnerability (SERVER-9878) (CVE-2013-3969)
- MongoDB PCRE Library Denial of Service Vulnerability (SERVER-17252) (CVE-2014-8964)
- MongoDB User Credentials Information Disclosure Vulnerability (SERVER-13644)
- MongoDB X509 Certificate Authentication Denial of Service Vulnerability (SERVER-13753) (CVE-2014-3971)
Nginx
PostgreSQL
- PostgreSQL Arbitrary SQL Statement Execution Vulnerability (CVE-2019-10208)
- PostgreSQL Enterprise DB Windows Installer Insecure Temporary File Vulnerability (CVE-2019-10210)
- PostgreSQL Hashed Subplan Cross-Type Comparison Memory Disclosure Vulnerability (CVE-2019-10209)
- PostgreSQL EnterpriseDB Windows Installer Bundled OpenSSL Arbitrary Code Execution Vulnerability (CVE-2019-10211)
Ruby
Webmin
- Webmin Expired Password Feature Remote Command Execution (CVE-2019-15107)
How to Update?
All Trustwave customers using the TrustKeeper Scan Engine receive the updates automatically as soon as an update is available. No action is required.