Ganeti Arbitrary Command Execution Vulnerability
BID:37422
Info
Ganeti Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 37422 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4261 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 17 2009 12:00AM |
| Updated: | Dec 28 2009 09:02PM |
| Credit: | The vendor. |
| Vulnerable: |
Ganeti Project Ganeti 2.0.4 Ganeti Project Ganeti 1.2.8 Ganeti Project Ganeti 1.2.6 Ganeti Project Ganeti 2.1.0 RC1 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
Ganeti Project Ganeti 2.0.5 Ganeti Project Ganeti 1.2.9 Ganeti Project Ganeti 2.1.0 RC2 |
Discussion
Ganeti Arbitrary Command Execution Vulnerability
Ganeti is prone to a vulnerability that lets attackers execute arbitrary commands in the context of the vulnerable application.
This issue may allow remote attackers to gain unauthorized access or local attackers to execute commands with elevated privileges, leading to a system compromise.
This issue affects versions prior to Ganeti 2.0.5, 1.2.9, and 2.1.0 rc2.
Ganeti is prone to a vulnerability that lets attackers execute arbitrary commands in the context of the vulnerable application.
This issue may allow remote attackers to gain unauthorized access or local attackers to execute commands with elevated privileges, leading to a system compromise.
This issue affects versions prior to Ganeti 2.0.5, 1.2.9, and 2.1.0 rc2.
Exploit / POC
Ganeti Arbitrary Command Execution Vulnerability
An attacker can use widely available tools and utilities to carry out attacks.
An attacker can use widely available tools and utilities to carry out attacks.
Solution / Fix
Ganeti Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
Debian Linux 5.0 hppa
Debian Linux 5.0 ia-64
Debian Linux 5.0 m68k
Debian Linux 5.0 arm
Debian Linux 5.0 armel
Debian Linux 5.0
Debian Linux 5.0 alpha
Debian Linux 5.0 amd64
Debian Linux 5.0 ia-32
Debian Linux 5.0 mips
Debian Linux 5.0 s/390
Debian Linux 5.0 mipsel
Debian Linux 5.0 powerpc
Debian Linux 5.0 sparc
Solution:
Updates are available. Please see the references for details.
Debian Linux 5.0 hppa
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 ia-64
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 m68k
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 arm
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 armel
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 alpha
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 amd64
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 ia-32
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 mips
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 s/390
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 mipsel
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 powerpc
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
Debian Linux 5.0 sparc
-
Debian ganeti_1.2.6-3+lenny2_all.deb
http://security.debian.org/pool/updates/main/g/ganeti/ganeti_1.2.6-3+l enny2_all.deb
References
Ganeti Arbitrary Command Execution Vulnerability
References:
References: