Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Tenable Nessus 10.12.5: Signaturpflicht für Plugin-Updates, Sicherheitsfixes
Tenable Nessus 10.12.5 verlangt für manuelle Plugin-Updates in Tenable Nessus und Tenable Nessus Manager nun die Signaturdatei und behebt mehrere Sicherheitslücken, darunter Speicherfehler im Plugin-Loader, fehlende Signaturprüfung beim Legacy-Update-Kanal und eine SQL-Injection beim Import von Scan-Policies.
ClosedChanged Functionality and Performance Enhancements
The following changes are included in Tenable Nessus 10.12.5:
- Manual plugin updates for both Tenable Nessus and Tenable Nessus Manager now require the signature file to process plugin updates. This change does not impact Tenable Security Center plugin updates, Tenable Nessus Manager's agent plugin updates, or Tenable Nessus application updates.
ClosedSecurity Updates
The following are security updates included in Tenable Nessus 10.12.5:
Fixed multiple memory-safety flaws in the plugin file loader.
Fixed an out-of-bounds memory access in the plugin execution engine's logic.
Fixed a denial-of-service condition where a crafted plugin file could trigger a crash-restart loop.
Fixed an out-of-bounds read in the plugin file parser that could expose internal scanner memory in diagnostic output.
Fixed a double-free memory corruption that could be triggered by a crafted plugin.
Fixed a vulnerability where plugin archives pushed through the legacy update channel were installed without signature verification. Uploaded plugin archives are now required to carry a valid Tenable signature before they are extracted or loaded.
Fixed a SQL injection vulnerability in the scan policy import functionality. …