PT-2011-1041 · Debian · Bcfg2

Stpierre

·

Publicado

2011-09-15

·

Atualizado

2011-09-23

·

CVE-2011-3211

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Bcfg2 versions 1.1.2 and earlier Bcfg2 version 1.2 prerelease
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in data received from a client. Multiple vulnerabilities in the Bcfg2 package of the Debian GNU/Linux operating system can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For Bcfg2 versions 1.1.2 and earlier, consider disabling the reception of client data until a patch is available. For Bcfg2 version 1.2 prerelease, restrict access to the server to minimize the risk of exploitation. As a temporary workaround, consider validating and sanitizing all client data to prevent the execution of arbitrary commands via shell metacharacters.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02946
CVE-2011-3211
DSA-2302-1

Produtos afetados

Bcfg2