CVE-2013-6765
Publication date 19 May 2014
Last updated 24 July 2024
Ubuntu priority
Description
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| openvas-server | ||
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
Notes
seth-arnold
I do not know if we are affected; I assigned this to the openvas-server package to ensure it does not get lost.