PT-2009-1003 · Ganglia · Ganglia

Spike Spiegel

·

Published

2009-01-21

·

Updated

2009-06-13

·

CVE-2009-0241

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ganglia version 3.1.1
Description The issue is related to a stack-based buffer overflow in the process path function, which can be exploited by remote attackers to cause a denial of service (crash) by sending a request to the gmetad service with a long pathname. Additionally, there are multiple vulnerabilities in the gmetad package that can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations For Ganglia version 3.1.1, consider disabling the process path function in the gmetad service as a temporary workaround to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01424
CVE-2009-0241
DSA-1710-1

Affected Products

Ganglia