Software Updates

Web Application Security – ModSecurity Commercial Rules, Update for December 2022 | Trustwave

Written by | Apr 25, 2022 5:10:00 PM

Summary

The latest update to the TrustKeeper scan engine that powers our Trustwave Vulnerability Management product (including both internal and external vulnerability scanning) is now available. Enjoy!

New Vulnerability Test Highlights

Some of the more interesting vulnerability tests we added recently are as follows:

CentOS (Credentialed Checks)

ClamAV

  • ClamAV CL_SCAN_GENERAL_COLLECT_METADATA Invalid Pointer Denial of Service (CVE-2022-20698)

Debian (Credentialed Checks)

Drupal

  • Drupal Core Guzzle Improper Input Validation Vulnerability (SA-CORE-2022-006) (CVE-2022-24775)

Fedora (Credentialed Checks)

  • Fedora 389-ds-base Security Update (FEDORA-2022-2558f14c58) (CVE-2022-0996)
  • Fedora buildah Security Update (FEDORA-2022-e6388650ea) (CVE-2022-27651)
  • Fedora chromium Security Update (FEDORA-2022-ba2c5339d4) (CVE-2022-1096)
  • Fedora cobbler Security Update (FEDORA-2022-ad2b0ad61b) (CVE-2022-0860)
  • Fedora crun Security Update (FEDORA-2022-10fd054d40) (CVE-2022-27650)
  • Fedora gdal Security Update (FEDORA-2022-cffca5dbf4) (CVE-2021-45943)
  • Fedora kernel Security Update (FEDORA-2022-8e3ac65667) (CVE-2022-1048)
  • Fedora mingw-fribidi Security Update (FEDORA-2022-56942dc7c5) (CVE-2022-25308, CVE-2022-25309, CVE-2022-25310)
  • Fedora mingw-openexr Security Update (FEDORA-2022-b0a85ed1b3) (CVE-2021-45942)
  • Fedora Multiple Packages Security Update (FEDORA-2022-1f981071eb) (CVE-2022-24724)
  • Fedora Multiple Packages Security Update (FEDORA-2022-ee15b98ea1) (CVE-2022-24303)
  • Fedora openssl Security Update (FEDORA-2022-9e88b5d8d7) (CVE-2022-0778)
  • Fedora phoronix-test-suite Security Update (FEDORA-2022-29c30bc7ef) (CVE-2022-0571)
  • Fedora rsh Security Update (FEDORA-2022-6748ae617b) (CVE-2019-7282)
  • Fedora skopeo Security Update (FEDORA-2022-6043a7b938) (CVE-2022-21698)
  • Fedora swaylock Security Update (FEDORA-2022-194c3da292) (CVE-2022-26530)

FreeBSD

Joomla

Microsoft

Mozilla Firefox

PHP

  • PHP FILTER_VALIDATE_FLOAT Use After Free Vulnerability (CVE-2021-21708)

Red Hat (Credentialed Checks)

SUSE Linux (Credentialed Checks)

Ubuntu (Credentialed Checks)

VMWare

How to Update?

All Trustwave customers using the TrustKeeper Scan Engine receive the updates automatically as soon as an update is available. No action is required.