Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.70238
Categoría:Debian Local Security Checks
Título:Debian Security Advisory DSA 2302-1 (bcfg2)
Resumen:The remote host is missing an update to bcfg2;announced via advisory DSA 2302-1.
Descripción:Summary:
The remote host is missing an update to bcfg2
announced via advisory DSA 2302-1.

Vulnerability Insight:
It has been discovered that the bcfg2 server, a configuration management
server for bcfg2 clients, is not properly sanitizing input from bcfg2
clients before passing it to various shell commands. This enables an
attacker in control of a bcfg2 client to execute arbitrary commands on
the server with root privileges.

For the oldstable distribution (lenny), this problem has been fixed in
version 0.9.5.7-1.1+lenny1.

For the stable distribution (squeeze), this problem has been fixed in
version 1.0.1-3+squeeze1

For the testing distribution (wheezy), this problem has been fixed in
version 1.1.2-2.

For the unstable distribution (sid), this problem has been fixed in
version 1.1.2-2.

Solution:
We recommend that you upgrade your bcfg2 packages.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-3211
BugTraq ID: 49414
http://www.securityfocus.com/bid/49414
Debian Security Information: DSA-2302 (Google Search)
http://www.debian.org/security/2011/dsa-2302
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066071.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066070.html
http://article.gmane.org/gmane.comp.sysutils.bcfg2.devel/4318
http://openwall.com/lists/oss-security/2011/09/01/1
http://openwall.com/lists/oss-security/2011/09/06/1
http://secunia.com/advisories/45807
http://secunia.com/advisories/45926
http://secunia.com/advisories/46042
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.