PT-2019-17666 · Revive Adserver · Revive Adserver

Publicado

2019-05-06

·

Atualizado

2019-12-16

·

CVE-2019-5434

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Revive Adserver versions prior to 4.2.0
Description The issue allows an attacker to send a specifically crafted payload to the XML-RPC invocation script, triggering the unserialize() call on the what parameter in the openads.spc RPC method. This could be used to perform various types of attacks, such as exploiting serialize-related PHP vulnerabilities or PHP object injection. There is an unconfirmed possibility that the vulnerability has been used by attackers to gain access to Revive Adserver instances and deliver malware to third-party websites.
Recommendations For versions prior to 4.2.0, update to version 4.2.0 to address the issue. As a temporary workaround, consider restricting access to the openads.spc RPC method until the update is applied. Avoid using the what parameter in the affected XML-RPC invocation script until the issue is resolved.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-5434

Produtos afetados

Revive Adserver