[R3] SecurityCenter 5.4 Fixes Multiple Third-party Library Vulnerabilities

Related Vulnerabilities: CVE-2016-4802   CVE-2016-0739   CVE-2016-0787  

SecurityCenter uses third-party libraries to provide certain standardized functionality. Two of these libraries were found to contain vulnerabilities and were fixed upstream. Those fixes have been integrated despite there being no known exploitation scenarios related to SecurityCenter. cURL / libcurl DLL Hijacking Arbitrary Code Execution cURL / libcurl lib/timeval.c curlx_tvdiff() Function timeval Handling Integer Overflow Unspecified Issue libssh / libssh2 Insecure Diffie-Hellman Secret Key Generation MitM Spoofing Note that the CVSSv2 score associated with this advisory is specific to libcurl's integration in SecurityCenter and assumes a worst-case scenario despite the integer overflow not being proven to result in code execution. Further, Tenable strongly recommends that SecurityCenter be installed on a subnet that is not Internet addressable.

Synopsis

SecurityCenter uses third-party libraries to provide certain standardized functionality. Two of these libraries were found to contain vulnerabilities and were fixed upstream. Those fixes have been integrated despite there being no known exploitation scenarios related to SecurityCenter.

  1. cURL / libcurl DLL Hijacking Arbitrary Code Execution
  2. cURL / libcurl lib/timeval.c curlx_tvdiff() Function timeval Handling Integer Overflow Unspecified Issue
  3. libssh / libssh4 Insecure Diffie-Hellman Secret Key Generation MitM Spoofing

Note that the CVSSv2 score associated with this advisory is specific to libcurl's integration in SecurityCenter and assumes a worst-case scenario despite the integer overflow not being proven to result in code execution. Further, Tenable strongly recommends that SecurityCenter be installed on a subnet that is not Internet addressable.

Solution

Tenable has released version 5.4 of SecurityCenter that addresses these issues. Upgrade information and a download can be obtained from:

http://static.tenable.com/prod_docs/upgrade_security_center.html