pen-test
[Top] [All Lists]

[Tool Update] SSA version 1.5.2 released

To: pen-test@securityfocus.com
Subject: [Tool Update] SSA version 1.5.2 released
From: "SD List" <list@security-database.com>
Date: Wed, 18 Jul 2007 14:24:55 +0200 (CEST)
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Importance: Normal
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Reply-to: list@security-database.com
Resent-date: Wed, 18 Jul 2007 08:45:21 -0600 (MDT)
Resent-from: pen-test-return-1078484623@securityfocus.com
Resent-message-id: <20070718144521.35051143785@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: SquirrelMail/1.4.4
SSA (Security System Analyzer) is a non-intrusive OVAL-Compatible policy
compliance and vulnerability assessment software. It provides auditors and
security officers a comprehensive solution to keep pace with security
compliance requirements (patch management, vulnerability management,
software inventories...)

Changelog for v.1.5.2

- Based on OVAL 5.3 build 20 (see OVAL project for more information)

- SSA now supports SCAP (Security Content Automation Protocol -
http://nvd.nist.gov/scap.cfm). The XML SCAP files are extracted using our
new SCAP Parser (SCAP_Patch_Extractor). The coming release of SSA should
be completely compatible with XCCDF (http://nvd.nist.gov/xccdf.cfm) .

- SSA now supports scan for missed patches (using SCAP format)
   * Added Windows XP Patches definition file
   * Added Windows Vista Patches definition file
   * Added Windows 2000 Patches definition file
   * Added Office 2007 Patches definition file
   * Added Internet explorer 7 patches definition file

- Updated OVAL XML Viewer Plugin
   * Updated database to 2039 definitions
   * Added support to CVE search (ex: CVE-2007-* will return all CVEs in
2007 used along with their appropriate OVALids.)
   * Bugs fixed

Documentation for 1.5.2 should be available by the end of the week.

Download it for free at www.security-database.com/ssa.php

Any suggestions, please report it to ssa@security-database.com.

Regards

Nabil OUCHN
Security-Database.com




------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/c/wf-spi
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>
  • [Tool Update] SSA version 1.5.2 released, SD List <=