PT-2015-1273 · Red Hat+1 · Setroubleshoot+2

Sebastian Krahmer

·

Publicado

2015-03-26

·

Atualizado

2023-02-13

·

CVE-2015-1815

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions setroubleshoot versions prior to 3.2.22
Description The issue is related to incorrect file name handling, which can be exploited by remote attackers to execute arbitrary commands by adding shell metacharacters to file names. This is specifically related to the get rpm nvr by file path temporary function in util.py.
Recommendations For versions prior to 3.2.22, update to version 3.2.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the get rpm nvr by file path temporary function in util.py until a patch is available.

Exploit

Correção

RCE

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-10303
CESA-2015_0729
CVE-2015-1815
RHSA-2015:0729
RHSA-2015_0729

Produtos afetados

Centos
Red Hat
Setroubleshoot