Red Hat 'redhat-ds-admin' Shell Command Injection and Security Bypass Vulnerabilities
BID:28802
Info
Red Hat 'redhat-ds-admin' Shell Command Injection and Security Bypass Vulnerabilities
| Bugtraq ID: | 28802 |
| Class: | Unknown |
| CVE: |
CVE-2008-0892 CVE-2008-0893 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2008 12:00AM |
| Updated: | May 06 2008 11:55PM |
| Credit: | Richard Megginson |
| Vulnerable: |
Redhat Directory Server 8 EL 5 Redhat Directory Server 8 EL 4 Redhat Directory Server 7.1 SP4 Redhat Directory Server 7.1 SP3 Redhat Directory Server 7.1 SP2 Redhat Directory Server 7.1 SP1 Redhat Directory Server 7.1 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 |
| Not Vulnerable: |
Redhat Directory Server 7.1 SP5 |
Discussion
Red Hat 'redhat-ds-admin' Shell Command Injection and Security Bypass Vulnerabilities
The 'redhat-ds-admin' application is prone to a command-injection issue and security-bypass issues that affect the Administration Server.
Attackers with access to the replication monitor web page can exploit the command-injection issue to execute arbitrary shell commands with the privileges of the Administration Server. Remote unauthenticated attackers can use the security-bypass vulnerabilities to access potentially sensitive information or perform certain unauthorized actions.
Note that combining the vulnerabilities would allow remote unauthorized attackers to execute arbitrary code with the privileges of the Administration Server.
NOTE: In default configurations, the Administration Server runs as unprivileged user 'nobody'.
These issues affect 'redhat-ds-admin' used with Red Hat Directory Server 8.
The 'redhat-ds-admin' application is prone to a command-injection issue and security-bypass issues that affect the Administration Server.
Attackers with access to the replication monitor web page can exploit the command-injection issue to execute arbitrary shell commands with the privileges of the Administration Server. Remote unauthenticated attackers can use the security-bypass vulnerabilities to access potentially sensitive information or perform certain unauthorized actions.
Note that combining the vulnerabilities would allow remote unauthorized attackers to execute arbitrary code with the privileges of the Administration Server.
NOTE: In default configurations, the Administration Server runs as unprivileged user 'nobody'.
These issues affect 'redhat-ds-admin' used with Red Hat Directory Server 8.
Exploit / POC
Red Hat 'redhat-ds-admin' Shell Command Injection and Security Bypass Vulnerabilities
Attackers can use readily available tools to launch attacks.
Attackers can use readily available tools to launch attacks.
Solution / Fix
Red Hat 'redhat-ds-admin' Shell Command Injection and Security Bypass Vulnerabilities
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
Red Hat 'redhat-ds-admin' Shell Command Injection and Security Bypass Vulnerabilities
References:
References: