cbrPager Archive Remote Command Execution Vulnerability
BID:29415
Info
cbrPager Archive Remote Command Execution Vulnerability
| Bugtraq ID: | 29415 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2008 12:00AM |
| Updated: | May 07 2015 05:03PM |
| Credit: | Mamoru Tasaka |
| Vulnerable: |
Red Hat Fedora 7 John Coppens cbrPager 0.9.16 Gentoo Linux |
| Not Vulnerable: |
John Coppens cbrPager 0.9.17 |
Discussion
cbrPager Archive Remote Command Execution Vulnerability
cbrPager is prone to a remote shell command-execution vulnerability because the application fails to sufficiently sanitize user-supplied data.
Successfully exploiting this issue will allow an attacker to execute arbitrary commands with the privileges of the user running the affected application.
cbrPager 0.9.16 is vulnerable; other versions may also be affected.
cbrPager is prone to a remote shell command-execution vulnerability because the application fails to sufficiently sanitize user-supplied data.
Successfully exploiting this issue will allow an attacker to execute arbitrary commands with the privileges of the user running the affected application.
cbrPager 0.9.16 is vulnerable; other versions may also be affected.
Exploit / POC
cbrPager Archive Remote Command Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
cbrPager Archive Remote Command Execution Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
cbrPager Archive Remote Command Execution Vulnerability
References:
References:
- Bugzilla Bug 448285: cbrpager: Command executions via improper shell escaping (Mamoru Tasaka)
- cbrPager Homepage (John Coppens)
- cbrpager-0.9.17 Changelog (John Coppens)