Beanstalk Job Data Remote Command Execution Vulnerability
BID:40516
Info
Beanstalk Job Data Remote Command Execution Vulnerability
| Bugtraq ID: | 40516 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2060 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2010 12:00AM |
| Updated: | May 07 2015 05:12PM |
| Credit: | Graham Barr |
| Vulnerable: |
Wildbit Beanstalk 1.4.5 Gentoo Linux |
| Not Vulnerable: |
Wildbit Beanstalk 1.4.6 |
Discussion
Beanstalk Job Data Remote Command Execution Vulnerability
Beanstalk is prone to a remote command-execution vulnerability because the software fails to adequately sanitize user-supplied input.
Successful exploiting this issue will allow attackers to execute Beanstalk client commands within the context of the affected application.
Versions prior to Beanstalk 1.4.6 are vulnerable.
Beanstalk is prone to a remote command-execution vulnerability because the software fails to adequately sanitize user-supplied input.
Successful exploiting this issue will allow attackers to execute Beanstalk client commands within the context of the affected application.
Versions prior to Beanstalk 1.4.6 are vulnerable.
Exploit / POC
Beanstalk Job Data Remote Command Execution Vulnerability
An attacker can exploit this issue by using readily available tools.
An attacker can exploit this issue by using readily available tools.
Solution / Fix
Beanstalk Job Data Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Beanstalk Job Data Remote Command Execution Vulnerability
References:
References:
- BeanStalk Homepage (Wildbit)
- Beanstalkd 1.4.6 Security Release Notes (Wildbit)
- Bugzilla Bug 322457 (Gentoo)