PT-2011-1041 · Debian · Bcfg2

Stpierre

·

Published

2011-09-15

·

Updated

2011-09-23

·

CVE-2011-3211

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Bcfg2 versions 1.1.2 and earlier Bcfg2 version 1.2 prerelease
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in data received from a client. Multiple vulnerabilities in the Bcfg2 package of the Debian GNU/Linux operating system can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For Bcfg2 versions 1.1.2 and earlier, consider disabling the reception of client data until a patch is available. For Bcfg2 version 1.2 prerelease, restrict access to the server to minimize the risk of exploitation. As a temporary workaround, consider validating and sanitizing all client data to prevent the execution of arbitrary commands via shell metacharacters.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02946
CVE-2011-3211
DSA-2302-1

Affected Products

Bcfg2