Software Updates

TrustKeeper Scan Engine Update for September 04, 2019

Written by | Sep 4, 2019 9:28:00 AM

Summary

The latest update to the TrustKeeper scan engine that powers our Trustwave Vulnerability Management product (including both internal and external vulnerability scanning) is now available. Enjoy!

New Vulnerability Test Highlights

Some of the more interesting vulnerability tests we added recently are as follows:

Apache

  • Apache HTTP Server mod_http2 Denial of Service Attack by Exhausting H2 Workers Vulnerability (httpd 2.4.41 Release) (CVE-2019-9517)
  • Apache HTTP Server mod_http2 Memory Corruption on Early Pushes Vulnerability (httpd 2.4.41 Release) (CVE-2019-10081)
  • Apache HTTP Server mod_http2 Read-After-Free in H2 Connection Shutdown Vulnerability (httpd 2.4.41 Release) (CVE-2019-10082)
  • Apache HTTP Server mod_proxy Error Page Cross-Site Scripting Vulnerability (httpd 2.4.41 Release) (CVE-2019-10092)
  • Apache HTTP Server mod_remoteip Stack Buffer Overflow and NULL Pointer Dereference Vulnerability (httpd 2.4.41 Release) (CVE-2019-10097)
  • Apache HTTP Server mod_rewrite Potential Open Redirect Vulnerability (httpd 2.4.41 Release) (CVE-2019-10098)
  • Apache Subversion svnserve get-deleted-rev Denial of Service Vulnerability (CVE-2018-11782)
  • Apache Subversion svnserve Remote Unauthenticated Denial of Service Vulnerability (CVE-2019-0203)

Cisco

  • Cisco ASA Smart Tunnel Vulnerabilities (cisco-sa-20190807-asa-multi, CSCvo78789) (CVE-2019-1945, CVE-2019-1944)
  • Cisco ASA Web-Based Management Interface Privilege Escalation Vulnerability (cisco-sa-20190807-asa-privescala, CSCvp09150) (CVE-2019-1934)

ClamAV

  • ClamAV NSIS bzip2 Decompression Out-of-Bounds Write Vulnerability (CVE-2019-12900)

cPanel

FreeBSD

  • FreeBSD bhyve Insufficient Validation of Guest-supplied Data Vulnerability (FreeBSD-SA-19:21.bhyve) (CVE-2019-5609)
  • FreeBSD bsnmp Insufficient Message Length Validation Vulnerabilities (FreeBSD-SA-19:20.bsnmp) (CVE-2019-5610)
  • FreeBSD bzip2 Multiple Vulnerabilities (FreeBSD-SA-19:18.bzip2) (CVE-2016-3189, CVE-2019-12900)
  • FreeBSD IPv6 Denial of Service Vulnerability (FreeBSD-SA-19:22.mbuf) (CVE-2019-5611)
  • FreeBSD Kernel Sound Module Memory Disclosure Vulnerability (FreeBSD-SA-19:23.midi) (CVE-2019-5612)
  • FreeBSD MLDv2 Out-of-bounds Memory Access Vulnerability (FreeBSD-SA-19:19.mldv2) (CVE-2019-5608)
  • FreeBSD mqueuefs Privilege EscalationVulnerability (FreeBSD-SA-19:24.mqueuefs) (CVE-2019-5603)

HP System Management

MongoDB

  • MongoDB - Unencrypted Communication Channel Accessibility
  • MongoDB Concurrency and Authentication - Improper internal system privileges (SERVER-9983) (CVE-2013-4650)
  • MongoDB JS Engine - V8 C++ bindings Remote Memory Corruption Vulnerability (SERVER-9878) (CVE-2013-3969)
  • MongoDB PCRE Library Denial of Service Vulnerability (SERVER-17252) (CVE-2014-8964)
  • MongoDB User Credentials Information Disclosure Vulnerability (SERVER-13644)
  • MongoDB X509 Certificate Authentication Denial of Service Vulnerability (SERVER-13753) (CVE-2014-3971)

Nginx

PostgreSQL

  • PostgreSQL Arbitrary SQL Statement Execution Vulnerability (CVE-2019-10208)
  • PostgreSQL Enterprise DB Windows Installer Insecure Temporary File Vulnerability (CVE-2019-10210)
  • PostgreSQL Hashed Subplan Cross-Type Comparison Memory Disclosure Vulnerability (CVE-2019-10209)
  • PostgreSQL EnterpriseDB Windows Installer Bundled OpenSSL Arbitrary Code Execution Vulnerability (CVE-2019-10211)

Ruby

Webmin

  • Webmin Expired Password Feature Remote Command Execution (CVE-2019-15107)

How to Update?

All Trustwave customers using the TrustKeeper Scan Engine receive the updates automatically as soon as an update is available. No action is required.