PT-2011-1041 · Debian · Bcfg2
Stpierre
·
Published
2011-09-15
·
Updated
2011-09-23
·
CVE-2011-3211
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Bcfg2 versions 1.1.2 and earlier
Bcfg2 version 1.2 prerelease
Description
The issue allows remote attackers to execute arbitrary commands via shell metacharacters in data received from a client. Multiple vulnerabilities in the Bcfg2 package of the Debian GNU/Linux operating system can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations
For Bcfg2 versions 1.1.2 and earlier, consider disabling the reception of client data until a patch is available.
For Bcfg2 version 1.2 prerelease, restrict access to the server to minimize the risk of exploitation.
As a temporary workaround, consider validating and sanitizing all client data to prevent the execution of arbitrary commands via shell metacharacters.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bcfg2