PT-2009-1003 · Ganglia · Ganglia
Spike Spiegel
·
Published
2009-01-21
·
Updated
2009-06-13
·
CVE-2009-0241
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ganglia version 3.1.1
Description
The issue is related to a stack-based buffer overflow in the
process path function, which can be exploited by remote attackers to cause a denial of service (crash) by sending a request to the gmetad service with a long pathname. Additionally, there are multiple vulnerabilities in the gmetad package that can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.Recommendations
For Ganglia version 3.1.1, consider disabling the
process path function in the gmetad service as a temporary workaround to prevent exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ganglia