PT-2009-5430 · Zmanda · Zmanda Recovery Manager For Mysql

Published

2009-09-08

·

Updated

2017-08-17

·

CVE-2009-3102

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Zmanda Recovery Manager (ZRM) for MySQL versions prior to 2.1.1
Description: The issue allows remote attackers to execute arbitrary commands. This is achieved through vectors involving a crafted MYSQL BINPATH variable in the doHotCopy subroutine in socket-server.pl.
Recommendations: For versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the doHotCopy subroutine in socket-server.pl to minimize the risk of exploitation. Avoid using the MYSQL BINPATH variable in the affected script until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3102

Affected Products

Zmanda Recovery Manager For Mysql