SB2014061808 - Improper Authentication in libcap-ng (Alpine package)



SB2014061808 - Improper Authentication in libcap-ng (Alpine package)

Published: June 18, 2014

Security Bulletin ID SB2014061808
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2013-3215)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.


Remediation

Install update from vendor's website.