[R2] SecurityCenter 5.6.2.1 Fixes One Third-party Vulnerability

Related Vulnerabilities: CVE-2018-7584  

SecurityCenter leverages third-party software to help provide underlying functionality. One of the third-party components (PHP) were found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution and in line with good practice, Tenable opted to upgrade the bundled PHP to address the potential impact of these issues on SecurityCenter. SecurityCenter 5.6.2.1 updates PHP to version 5.6.34 to address the identified vulnerabilities. References for the issues are below: PHP Stack Buffer Overflow Vulnerability (CVE-2018-7584) Note: A separate stand-alone patch has also been released to update PHP to version 5.6.34 in SecurityCenter versions 5.X.

Synopsis

SecurityCenter leverages third-party software to help provide underlying functionality. One of the third-party components (PHP) were found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution and in line with good practice, Tenable opted to upgrade the bundled PHP to address the potential impact of these issues on SecurityCenter. SecurityCenter 5.6.2.1 updates PHP to version 5.6.34 to address the identified vulnerabilities.

References for the issues are below:
  • PHP Stack Buffer Overflow Vulnerability (CVE-2018-7584)


Note: A separate stand-alone patch has also been released to update PHP to version 5.6.34 in SecurityCenter versions 5.X.

Solution

Tenable has released SecurityCenter 5.6.2.1 to address this issue, as well as a separate stand-alone PHP patch for SecurityCenter versions 5.X. The new version and stand-alone patch can be obtained from the Tenable Support Portal (https://support.tenable.com/support-center/index.php?x=&mod_id=160).