PT-2014-5353 · Red Hat · Red Hat Cloudforms

Published

2014-07-07

·

Updated

2023-02-13

·

CVE-2014-3486

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat CloudForms versions prior to 5.2.4.2
Description The issue allows local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name. This is due to vulnerabilities in the shell exec function in lib/util/MiqSshUtilV1.rb and the temp cmd file function in lib/util/MiqSshUtilV2.rb.
Recommendations For versions prior to 5.2.4.2, update to version 5.2.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the shell exec function and the temp cmd file function to minimize the risk of exploitation.

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2014-3486
RHSA-2014:0816

Affected Products

Red Hat Cloudforms