Bcfg2 'Trigger' Plugin Remote Command Injection Vulnerability
BID:54217
Info
Bcfg2 'Trigger' Plugin Remote Command Injection Vulnerability
| Bugtraq ID: | 54217 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-3366 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2012 12:00AM |
| Updated: | Apr 13 2015 09:38PM |
| Credit: | Bcfg2 |
| Vulnerable: |
Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Bcfg2 Bcfg2 1.1.2 Bcfg2 Bcfg2 1.0.1 Bcfg2 Bcfg2 0.9.6 Bcfg2 Bcfg2 1.2.2 Bcfg2 Bcfg2 1.1 Bcfg2 Bcfg2 0.9.5.7 |
| Not Vulnerable: | |
Discussion
Bcfg2 'Trigger' Plugin Remote Command Injection Vulnerability
Bcfg2 is prone to a remote command-injection vulnerability due to a failure to properly sanitize user-supplied input in the 'Trigger' plugin.
An attacker can exploit this vulnerability to inject and execute arbitrary commands within the context of the affected application. This may facilitate a complete system compromise.
Bcfg2 is prone to a remote command-injection vulnerability due to a failure to properly sanitize user-supplied input in the 'Trigger' plugin.
An attacker can exploit this vulnerability to inject and execute arbitrary commands within the context of the affected application. This may facilitate a complete system compromise.
Exploit / POC
Bcfg2 'Trigger' Plugin Remote Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Bcfg2 'Trigger' Plugin Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Bcfg2 'Trigger' Plugin Remote Command Injection Vulnerability
References:
References:
- Bcfg2 Homepage (Bcfg2)
- Changeset (Bcfg2)
- bcfg2: arbitrary code execution flaw in Trigger plugin (Red Hat)