Rocky Linux 8 [CIQ] 安全性更新:libiscsi / libiscsi-debuginfo / libiscsi-debugsource / etc 多個弱點 (crlsa-2019_3345)

high Nessus Plugin ID 356824

概要

Rocky Linux 主機缺少一或多個安全性更新。

說明

Rocky Linux 8 主機已安裝的套件會受到 CIQ crlsa-2019_3345 公告中提及的多個弱點影響。

* ntfs-3g:堆積型緩衝區溢位導致本機 root 權限提升 (CVE-2019-9755)

* QEMU:slirp:由於未初始化的堆疊變數 (CVE-2019-9824),tcp_emu() 中存在資訊洩露

* QEMU:qxl:釋放 spice 資源時出現 null 指標解除參照 (CVE-2019-12155)

Tenable 已直接從 CIQ 安全性公告中擷取上述描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

根據 CIQ 公告 crlsa-2019_3345中的指引更新受影響的套件。

另請參閱

https://access.redhat.com/errata/RHSA-2019:3345

https://bugzilla.redhat.com/show_bug.cgi?id=1531543

https://bugzilla.redhat.com/show_bug.cgi?id=1662272

https://bugzilla.redhat.com/show_bug.cgi?id=1664463

https://bugzilla.redhat.com/show_bug.cgi?id=1667249

https://bugzilla.redhat.com/show_bug.cgi?id=1673010

https://bugzilla.redhat.com/show_bug.cgi?id=1673396

https://bugzilla.redhat.com/show_bug.cgi?id=1673401

https://bugzilla.redhat.com/show_bug.cgi?id=1678515

https://bugzilla.redhat.com/show_bug.cgi?id=1678979

https://bugzilla.redhat.com/show_bug.cgi?id=1679483

https://bugzilla.redhat.com/show_bug.cgi?id=1679966

https://bugzilla.redhat.com/show_bug.cgi?id=1680231

https://bugzilla.redhat.com/show_bug.cgi?id=1683681

https://bugzilla.redhat.com/show_bug.cgi?id=1684383

https://bugzilla.redhat.com/show_bug.cgi?id=1685151

https://bugzilla.redhat.com/show_bug.cgi?id=1686895

https://bugzilla.redhat.com/show_bug.cgi?id=1687541

https://bugzilla.redhat.com/show_bug.cgi?id=1687596

https://bugzilla.redhat.com/show_bug.cgi?id=1688062

https://bugzilla.redhat.com/show_bug.cgi?id=1689297

https://bugzilla.redhat.com/show_bug.cgi?id=1691356

https://bugzilla.redhat.com/show_bug.cgi?id=1691624

https://bugzilla.redhat.com/show_bug.cgi?id=1693299

https://bugzilla.redhat.com/show_bug.cgi?id=1693433

https://bugzilla.redhat.com/show_bug.cgi?id=1694148

https://bugzilla.redhat.com/show_bug.cgi?id=1697627

https://bugzilla.redhat.com/show_bug.cgi?id=1698133

https://bugzilla.redhat.com/show_bug.cgi?id=1707192

https://bugzilla.redhat.com/show_bug.cgi?id=1707598

https://bugzilla.redhat.com/show_bug.cgi?id=1707706

https://bugzilla.redhat.com/show_bug.cgi?id=1710575

https://bugzilla.redhat.com/show_bug.cgi?id=1712670

https://bugzilla.redhat.com/show_bug.cgi?id=1712810

https://bugzilla.redhat.com/show_bug.cgi?id=1712946

https://bugzilla.redhat.com/show_bug.cgi?id=1714933

https://bugzilla.redhat.com/show_bug.cgi?id=1716347

https://bugzilla.redhat.com/show_bug.cgi?id=1716907

https://bugzilla.redhat.com/show_bug.cgi?id=1716908

https://bugzilla.redhat.com/show_bug.cgi?id=1717088

https://bugzilla.redhat.com/show_bug.cgi?id=1719578

https://bugzilla.redhat.com/show_bug.cgi?id=1721434

https://bugzilla.redhat.com/show_bug.cgi?id=1721983

https://bugzilla.redhat.com/show_bug.cgi?id=1722668

https://bugzilla.redhat.com/show_bug.cgi?id=1722735

https://bugzilla.redhat.com/show_bug.cgi?id=1727821

https://bugzilla.redhat.com/show_bug.cgi?id=1728530

https://bugzilla.redhat.com/show_bug.cgi?id=1728657

https://bugzilla.redhat.com/show_bug.cgi?id=1728958

https://bugzilla.redhat.com/show_bug.cgi?id=1729675

https://bugzilla.redhat.com/show_bug.cgi?id=1732642

https://bugzilla.redhat.com/show_bug.cgi?id=1737790

https://bugzilla.redhat.com/show_bug.cgi?id=1738839

https://bugzilla.redhat.com/show_bug.cgi?id=1738886

https://bugzilla.redhat.com/show_bug.cgi?id=1740797

https://bugzilla.redhat.com/show_bug.cgi?id=1741825

https://bugzilla.redhat.com/show_bug.cgi?id=1741837

https://bugzilla.redhat.com/show_bug.cgi?id=1742819

https://bugzilla.redhat.com/show_bug.cgi?id=1744415

https://bugzilla.redhat.com/show_bug.cgi?id=1747185

https://bugzilla.redhat.com/show_bug.cgi?id=1747440

https://bugzilla.redhat.com/show_bug.cgi?id=1749227

https://errata.build.resf.org/RLSA-2019:3345

http://www.nessus.org/u?b19467e9

http://www.nessus.org/u?d26b9ed2

Plugin 詳細資訊

嚴重性: High

ID: 356824

檔案名稱: ciq_rocky_linux_8_crlsa-2019_3345.nasl

版本: 1.1

類型: Local

已發布: 2026/10/1

已更新: 2026/10/1

支援的感應器: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 4.9

百分位數: 57.12

Vendor

Vendor Severity: Unknown

CVSS v2

風險因素: Medium

基本分數: 4.4

時間性分數: 3.4

媒介: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS 評分資料來源: CVE-2019-9755

CVSS v3

風險因素: High

基本分數: 7

時間性分數: 6.3

媒介: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

弱點資訊

必要的 KB 項目: Host/OS/extended-third-party, Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2019/11/5

弱點發布日期: 2019/3/1

參考資訊

CVE: CVE-2019-12155, CVE-2019-9755, CVE-2019-9824