CVE-2017-9333
Summary
| CVE | CVE-2017-9333 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-18 01:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-controlled web site with a Trojan horse package. This has security implications in cases where untrusted users can trigger CallOPKG calls, and these users can enter an arbitrary URL in an input field, even though that input field was only intended for a package name. This threat model may be relevant in the latest versions of third-party products that bundle OpenWebif, i.e., set-top box products. The issue of Trojan horse packages does NOT have security implications in cases where the attacker has full OpenWebif access. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openwebif Project | Openwebif | 1.2.5 | All | All | All |
| Application | Openwebif Project | Openwebif | 1.2.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Remote code execution via IpkgController improper input validation. · Issue #619 · E2OpenPlugins/e2openplugin-OpenWebif · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| Bandit Output · Issue #621 · E2OpenPlugins/e2openplugin-OpenWebif · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.