Mcafee Foundstone Fsl Update 2019-Jul-03
Total Page:16
File Type:pdf, Size:1020Kb
2019-JUL-04 FSL version 7.6.118 MCAFEE FOUNDSTONE FSL UPDATE To better protect your environment McAfee has created this FSL check update for the Foundstone Product Suite. The following is a detailed summary of the new and updated checks included with this release. NEW CHECKS 25337 - Mozilla Thunderbird Multiple Vulnerabilities Prior To 60.7.1 Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS) Risk Level: High CVE: CVE-2019-11703, CVE-2019-11704, CVE-2019-11705, CVE-2019-11706 Description Multiple vulnerabilities are present in some versions of Mozilla Thunderbird. Observation Mozilla Thunderbird is an open-source email, newsgroup, news feed, and chat client. Multiple vulnerabilities are present in some versions of Mozilla Thunderbird. The flaws lie in several components. Successful exploitation could allow an attacker to cause a denial of service condition, or execute arbitrary code. 25341 - Mozilla Thunderbird Multiple Vulnerabilities Prior To 60.7.2 Category: Windows Host Assessment -> Miscellaneous (CATEGORY REQUIRES CREDENTIALS) Risk Level: High CVE: CVE-2019-11707, CVE-2019-11708 Description Multiple vulnerabilities are present in some versions of Mozilla Thunderbird. Observation Mozilla Thunderbird is an open-source email, newsgroup, news feed, and chat client. Multiple vulnerabilities are present in some versions of Mozilla Thunderbird. The flaws lie in several components. Successful exploitation could allow an attacker to cause a denial of service condition, or execute arbitrary code. 148110 - SuSE Linux 15.0, 15.1, 42.3 openSUSE-SU-2019:1666-1 Update Is Not Installed Category: SSH Module -> NonIntrusive -> SuSE Patches and Hotfixes Risk Level: High CVE: CVE-2019-5787, CVE-2019-5788, CVE-2019-5789, CVE-2019-5790, CVE-2019-5791, CVE-2019-5792, CVE-2019-5793, CVE-2019-5794, CVE-2019-5795, CVE-2019-5796, CVE-2019-5797, CVE-2019-5798, CVE-2019-5799, CVE-2019-5800, CVE- 2019-5801, CVE-2019-5802, CVE-2019-5803, CVE-2019-5804, CVE-2019-5805, CVE-2019-5806, CVE-2019-5807, CVE-2019- 5808, CVE-2019-5809, CVE-2019-5810, CVE-2019-5811, CVE-2019-5812, CVE-2019-5813, CVE-2019-5814, CVE-2019-5815, CVE-2019-5816, CVE-2019-5817, CVE-2019-5818, CVE-2019-5819, CVE-2019-5820, CVE-2019-5821, CVE-2019-5822, CVE- 2019-5823, CVE-2019-5824, CVE-2019-5827, CVE-2019-5828, CVE-2019-5829, CVE-2019-5830, CVE-2019-5831, CVE-2019- 5832, CVE-2019-5833, CVE-2019-5834, CVE-2019-5835, CVE-2019-5836, CVE-2019-5837, CVE-2019-5838, CVE-2019-5839, CVE-2019-5840, CVE-2019-5842 Description The scan detected that the host is missing the following update: openSUSE-SU-2019:1666-1 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: https://lists.opensuse.org/opensuse-updates/2019-06/msg00186.html https://lists.opensuse.org/opensuse-updates/2019-06/msg00187.html SuSE Linux 15.0 x86_64 chromium-debugsource-75.0.3770.90-lp150.218.4 chromedriver-75.0.3770.90-lp150.218.4 chromium-debuginfo-75.0.3770.90-lp150.218.4 chromedriver-debuginfo-75.0.3770.90-lp150.218.4 chromium-75.0.3770.90-lp150.218.4 SuSE Linux 42.3 x86_64 chromium-75.0.3770.90-217.1 chromedriver-75.0.3770.90-217.1 chromium-debuginfo-75.0.3770.90-217.1 chromium-debugsource-75.0.3770.90-217.1 chromedriver-debuginfo-75.0.3770.90-217.1 SuSE Linux 15.1 x86_64 chromium-debuginfo-75.0.3770.90-lp151.2.9.3 chromium-75.0.3770.90-lp151.2.9.3 chromium-debugsource-75.0.3770.90-lp151.2.9.3 chromedriver-debuginfo-75.0.3770.90-lp151.2.9.3 chromedriver-75.0.3770.90-lp151.2.9.3 160581 - CentOS 7 CESA-2019-1619 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Cent OS Patches and Hotfixes Risk Level: High CVE: CVE-2019-12735 Description The scan detected that the host is missing the following update: CESA-2019-1619 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: http://lists.centos.org/pipermail/centos-announce/2019-July/023345.html CentOS 7 x86_64 vim-X11-7.4.160-6.el7_6 vim-enhanced-7.4.160-6.el7_6 vim-common-7.4.160-6.el7_6 vim-minimal-7.4.160-6.el7_6 vim-filesystem-7.4.160-6.el7_6 160584 - CentOS 6 CESA-2019-1604 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Cent OS Patches and Hotfixes Risk Level: High CVE: CVE-2019-11707, CVE-2019-11708 Description The scan detected that the host is missing the following update: CESA-2019-1604 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: http://lists.centos.org/pipermail/centos-announce/2019-July/023346.html CentOS 6 x86_64 firefox-60.7.2-1.el6.centos i686 firefox-60.7.2-1.el6.centos 160585 - CentOS 7 CESA-2019-1603 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Cent OS Patches and Hotfixes Risk Level: High CVE: CVE-2019-11707, CVE-2019-11708 Description The scan detected that the host is missing the following update: CESA-2019-1603 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: http://lists.centos.org/pipermail/centos-announce/2019-July/023342.html CentOS 7 x86_64 firefox-60.7.2-1.el7.centos i686 firefox-60.7.2-1.el7.centos 163904 - Oracle Enterprise Linux ELSA-2019-1652 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Oracle Enterprise Linux Patches and Hotfixes Risk Level: High CVE: CVE-2016-0787, CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3862, CVE-2019-3863 Description The scan detected that the host is missing the following update: ELSA-2019-1652 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: http://oss.oracle.com/pipermail/el-errata/2019-July/008872.html OEL6 x86_64 libssh2-devel-1.4.2-3.0.1.el6_10.1 libssh2-1.4.2-3.0.1.el6_10.1 libssh2-docs-1.4.2-3.0.1.el6_10.1 i386 libssh2-devel-1.4.2-3.0.1.el6_10.1 libssh2-1.4.2-3.0.1.el6_10.1 libssh2-docs-1.4.2-3.0.1.el6_10.1 183011 - FreeBSD PostgreSQL Stack-based Buffer Overflow Via Setting A Password (245629d4-991e-11e9-82aa- 6cc21735f730) Category: SSH Module -> NonIntrusive -> FreeBSD Patches and Hotfixes Risk Level: High CVE: CVE-2019-10164 Description The scan detected that the host is missing the following update: PostgreSQL -- Stack-based buffer overflow via setting a password (245629d4-991e-11e9-82aa-6cc21735f730) Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: http://www.vuxml.org/freebsd/245629d4-991e-11e9-82aa-6cc21735f730.html Affected packages: postgresql11-server < 11.4 postgresql10-server < 10.9 196360 - Red Hat Enterprise Linux RHSA-2019-1652 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Red Hat Enterprise Linux Patches and Hotfixes Risk Level: High CVE: CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3863 Description The scan detected that the host is missing the following update: RHSA-2019-1652 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: http://www.redhat.com/archives/rhsa-announce/2019-July/msg00001.html RHEL6D x86_64 libssh2-1.4.2-3.el6_10.1 libssh2-devel-1.4.2-3.el6_10.1 libssh2-debuginfo-1.4.2-3.el6_10.1 libssh2-docs-1.4.2-3.el6_10.1 i386 libssh2-1.4.2-3.el6_10.1 libssh2-devel-1.4.2-3.el6_10.1 libssh2-debuginfo-1.4.2-3.el6_10.1 libssh2-docs-1.4.2-3.el6_10.1 RHEL6S i386 libssh2-1.4.2-3.el6_10.1 libssh2-devel-1.4.2-3.el6_10.1 libssh2-debuginfo-1.4.2-3.el6_10.1 libssh2-docs-1.4.2-3.el6_10.1 x86_64 libssh2-1.4.2-3.el6_10.1 libssh2-devel-1.4.2-3.el6_10.1 libssh2-debuginfo-1.4.2-3.el6_10.1 libssh2-docs-1.4.2-3.el6_10.1 RHEL6WS x86_64 libssh2-debuginfo-1.4.2-3.el6_10.1 libssh2-1.4.2-3.el6_10.1 i386 libssh2-debuginfo-1.4.2-3.el6_10.1 libssh2-1.4.2-3.el6_10.1 196364 - Red Hat Enterprise Linux RHSA-2019-1619 Update Is Not Installed Category: SSH Module -> NonIntrusive -> Red Hat Enterprise Linux Patches and Hotfixes Risk Level: High CVE: CVE-2019-12735 Description The scan detected that the host is missing the following update: RHSA-2019-1619 Observation Updates often remediate critical security problems that should be quickly addressed. For more information see: http://www.redhat.com/archives/rhsa-announce/2019-June/msg00058.html RHEL7D x86_64 vim-X11-7.4.160-6.el7_6 vim-filesystem-7.4.160-6.el7_6 vim-enhanced-7.4.160-6.el7_6 vim-common-7.4.160-6.el7_6 vim-debuginfo-7.4.160-6.el7_6 vim-minimal-7.4.160-6.el7_6 RHEL7S x86_64 vim-X11-7.4.160-6.el7_6 vim-filesystem-7.4.160-6.el7_6 vim-enhanced-7.4.160-6.el7_6 vim-common-7.4.160-6.el7_6 vim-debuginfo-7.4.160-6.el7_6 vim-minimal-7.4.160-6.el7_6 RHEL7WS x86_64 vim-X11-7.4.160-6.el7_6 vim-filesystem-7.4.160-6.el7_6 vim-enhanced-7.4.160-6.el7_6 vim-common-7.4.160-6.el7_6 vim-debuginfo-7.4.160-6.el7_6 vim-minimal-7.4.160-6.el7_6 25336 - Cisco NX-OS CLI Command Software Image Signature Verification Vulnerabilities (cisco-sa-20190515-nxos- sisv2) Category: SSH Module -> NonIntrusive -> SSH Miscellaneous Risk Level: High CVE: CVE-2019-1811, CVE-2019-1812, CVE-2019-1813 Description Multiple vulnerabilities are present in some versions of Cisco NX-OS Software.