PT-2009-1003 · Ganglia · Ganglia

Spike Spiegel

·

Publicado

2009-01-21

·

Atualizado

2009-06-13

·

CVE-2009-0241

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ganglia version 3.1.1
Description The issue is related to a stack-based buffer overflow in the process path function, which can be exploited by remote attackers to cause a denial of service (crash) by sending a request to the gmetad service with a long pathname. Additionally, there are multiple vulnerabilities in the gmetad package that can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations For Ganglia version 3.1.1, consider disabling the process path function in the gmetad service as a temporary workaround to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01424
CVE-2009-0241
DSA-1710-1

Produtos afetados

Ganglia