PT-2005-3387 · Rapid7 · Metasploit Framework

Publicado

2005-08-07

·

Atualizado

2017-07-11

·

CVE-2005-2482

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Metasploit Framework versions 2.4 and earlier
Description The issue concerns the StateToOptions function in msfweb, which is part of the Metasploit Framework. When running in defanged mode (with the -D option), this function allows attackers to modify temporary environment variables before the " Defanged" environment option is checked. This occurs during the processing of the Exploit command.
Recommendations For Metasploit Framework versions 2.4 and earlier, consider disabling the StateToOptions function or defanged mode until a fix is available to prevent potential exploitation. Restrict access to the Exploit command to minimize the risk of modification of temporary environment variables.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2482

Produtos afetados

Metasploit Framework