Bcfg2 Remote Command Injection Vulnerability
BID:49414
Info
Bcfg2 Remote Command Injection Vulnerability
| Bugtraq ID: | 49414 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3211 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2011 12:00AM |
| Updated: | Apr 13 2015 09:21PM |
| Credit: | Bcfg2 |
| Vulnerable: |
Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Bcfg2 Bcfg2 1.1.2 Bcfg2 Bcfg2 1.0.1 Bcfg2 Bcfg2 0.9.6 Bcfg2 Bcfg2 1.1 Bcfg2 Bcfg2 0.9.5.7 |
| Not Vulnerable: | |
Discussion
Bcfg2 Remote Command Injection Vulnerability
Bcfg2 is prone to a remote command-injection vulnerability due to a failure to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to inject and execute arbitrary commands within the context of the affected application. This may facilitate a complete system compromise.
Bcfg2 is prone to a remote command-injection vulnerability due to a failure to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to inject and execute arbitrary commands within the context of the affected application. This may facilitate a complete system compromise.
Exploit / POC
Bcfg2 Remote Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Bcfg2 Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Bcfg2 Remote Command Injection Vulnerability
References:
References:
- Bcfg2 Homepage (Bcfg2)
- CVE request for bcfg2 (remote root) (Jonathan Wiltshire)
- Unescaped shell command vulnerabilities (Debian)