SCAP Feed Release Update: 31-Oct-2014

  • Post author:
  • Reading time:22 mins read
  • Post category:SCAP Feed

The following SCAP content has been released to SCAP Repo and SecPod ANCOR. SecPod Saner will automatically pull the relevant content on its next scheduled update.

oval:org.secpod.oval:def:21532 CVE-2010-4820, Untrusted search path vulnerability in Ghostscript via a Trojan horse Postscript library file
oval:org.secpod.oval:def:21527 CVE-2014-3694, Information disclosure vulnerability in libpurple in Pidgin via a crafted certificate
oval:org.secpod.oval:def:21528 CVE-2014-3695, Denial of service vulnerability in libpurple in Pidgin via a large length value in an emoticon response
oval:org.secpod.oval:def:21529 CVE-2014-3696, Denial of service vulnerability in libpurple in Pidgin via a crafted server message
oval:org.secpod.oval:def:21530 CVE-2014-3697, Absolute path traversal vulnerability in libpurple in Pidgin via a drive name in a tar archive of a smiley theme
oval:org.secpod.oval:def:21531 CVE-2014-3698, Information disclosure vulnerability in libpurple in Pidgin via a crafted XMPP message
oval:org.secpod.oval:def:21513 cpe:/a:freerdp_project:freerdp, freerdp package is installed
oval:org.secpod.oval:def:21521 CVE-2014-4207, Unspecified vulnerability in MySQL and MariaDB via vectors related to SROPTZR
oval:org.secpod.oval:def:21522 CVE-2014-4260, Unspecified vulnerability in MySQL and MariaDB via vectors related to SRCHAR
oval:org.secpod.oval:def:21523 CVE-2014-4020, Denial of service vulnerability in Wireshark via a crafted packet
oval:org.secpod.oval:def:21525 CVE-2014-0247, Unspecified vulnerability in LibreOffice via unspecified vectors
oval:org.secpod.oval:def:21524 CVE-2014-0791, Integer overflow vulnerability in FreeRDP via a large ScopeCount value in a Scope List
oval:org.secpod.oval:def:21526 CVE-2014-0249, Security bypass vulnerability in sssd via unspecified vectors
oval:org.secpod.oval:def:21514 cpe:/a:mariadb:mariadb55-mariadb, mariadb55-mariadb package is installed
oval:org.secpod.oval:def:21515 CVE-2014-0209, Multiple integer overflow vulnerabilities in x.Org libXfont
oval:org.secpod.oval:def:21516 CVE-2014-0210, Multiple buffer overflow vulnerabilities in x.Org libXfont via a crafted xfs protocol reply
oval:org.secpod.oval:def:21517 CVE-2014-0211, Multiple integer overflow vulnerabilities in x.Org libXfont via a crafted xfs reply
oval:org.secpod.oval:def:21518 CVE-2014-4243, Unspecified vulnerability in MySQL and MariaDB via vectors related to ENFED
oval:org.secpod.oval:def:21519 CVE-2014-4258, Unspecified vulnerability in MySQL and MariaDB via vectors related to SRINFOSC
oval:org.secpod.oval:def:21520 CVE-2014-2494, Unspecified vulnerability in MySQL and MariaDB via vectors related to ENARC
oval:org.secpod.oval:def:702264 CVE-2014-3660,
USN-2389-1,
USN-2389-1 — libxml2 vulnerability
oval:org.secpod.oval:def:702265 CVE-2014-3694,
CVE-2014-3695,
CVE-2014-3696,
CVE-2014-3698,
USN-2390-1,
USN-2390-1 — pidgin vulnerabilities
oval:org.secpod.oval:def:601816 CVE-2014-8761,
CVE-2014-8762,
CVE-2014-8763,
CVE-2014-8764,
DSA-3059-1,
DSA-3059-1 dokuwiki — dokuwiki
oval:org.secpod.oval:def:601817 CVE-2014-3684,
DSA-3058-1,
DSA-3058-1 torque — torque
oval:org.secpod.oval:def:1500777 CVE-2014-3634,
ELSA-2014-1671,
ELSA-2014-1671 — Oracle rsyslog5
oval:org.secpod.oval:def:1500778 CVE-2014-6421,
CVE-2014-6423,
CVE-2014-6424,
CVE-2014-6425,
CVE-2014-6426,
CVE-2014-6427,
CVE-2014-6428,
CVE-2014-6429,
ELSA-2014-1676,
ELSA-2014-1676 — Oracle wireshark
oval:org.secpod.oval:def:1500779 CVE-2012-6647,
CVE-2013-1860,
CVE-2013-2141,
CVE-2013-2596,
CVE-2013-2929,
CVE-2013-4470,
CVE-2013-4483,
CVE-2013-4588,
CVE-2013-6367,
CVE-2013-6368,
CVE-2013-6378,
CVE-2013-6383,
CVE-2013-6405,
CVE-2013-7271,
CVE-2013-7339,
CVE-2014-0055,
CVE-2014-0069,
CVE-2014-0077,
CVE-2014-0101,
CVE-2014-0181,
CVE-2014-0196,
CVE-2014-0203,
CVE-2014-0205,
CVE-2014-1737,
CVE-2014-1738,
CVE-2014-1874,
CVE-2014-2523,
CVE-2014-2672,
CVE-2014-2678,
CVE-2014-2706,
CVE-2014-2851,
CVE-2014-3122,
CVE-2014-3144,
CVE-2014-3145,
CVE-2014-3153,
CVE-2014-3601,
CVE-2014-3917,
CVE-2014-4608,
CVE-2014-4653,
CVE-2014-4654,
CVE-2014-4655,
CVE-2014-4667,
CVE-2014-4699,
CVE-2014-4943,
CVE-2014-5045,
CVE-2014-5077,
ELSA-2014-1392,
ELSA-2014-1392 — Oracle kernel_python-perf_perf
oval:org.secpod.oval:def:1500780 CVE-2014-3634,
ELSA-2014-1654,
ELSA-2014-1654 — Oracle rsyslog7
oval:org.secpod.oval:def:1500781 CVE-2014-6457,
CVE-2014-6468,
CVE-2014-6502,
CVE-2014-6504,
CVE-2014-6506,
CVE-2014-6511,
CVE-2014-6512,
CVE-2014-6517,
CVE-2014-6519,
CVE-2014-6531,
CVE-2014-6558,
CVE-2014-6562,
ELSA-2014-1636,
ELSA-2014-1636 — Oracle java-1.8.0-openjdk
oval:org.secpod.oval:def:1500782 CVE-2014-6421,
CVE-2014-6423,
CVE-2014-6424,
CVE-2014-6425,
CVE-2014-6426,
CVE-2014-6427,
CVE-2014-6428,
CVE-2014-6429,
ELSA-2014-1676,
ELSA-2014-1676 — Oracle wireshark
oval:org.secpod.oval:def:1500783 CVE-2014-6421,
CVE-2014-6423,
CVE-2014-6425,
CVE-2014-6428,
CVE-2014-6429,
ELSA-2014-1677,
ELSA-2014-1677 — Oracle wireshark
oval:org.secpod.oval:def:1500784 CVE-2014-3634,
ELSA-2014-1671,
ELSA-2014-1671 — Oracle rsyslog