CVE-2013-6766
Publication date 19 May 2014
Last updated 24 July 2024
Ubuntu priority
Description
OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP commands via a crafted OAP request for version information, which causes the state to be set to CLIENT_AUTHENTIC.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| openvas-server | ||
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
Notes
seth-arnold
I do not know if we are affected; I assigned this to the openvas-server package to ensure it does not get lost.