Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
BID:57314
Info
Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
| Bugtraq ID: | 57314 |
| Class: | Design Error |
| CVE: |
CVE-2012-5649 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2013 12:00AM |
| Updated: | Apr 09 2013 12:38PM |
| Credit: | Jan Lehnardt |
| Vulnerable: |
Apache Software Foundation CouchDB 1.0.2 Apache Software Foundation CouchDB 1.0.1 Apache Software Foundation CouchDB 1.0 |
| Not Vulnerable: | |
Discussion
Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
Apache CouchDB is prone to a remote-code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks may cause denial-of-service conditions.
Apache CouchDB 1.0.3, 1.1.1, 1.2.0, and prior versions are vulnerable.
Apache CouchDB is prone to a remote-code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed attacks may cause denial-of-service conditions.
Apache CouchDB 1.0.3, 1.1.1, 1.2.0, and prior versions are vulnerable.
Exploit / POC
Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
Solution:
A vendor patch is available. Please see the references for more information.
Solution:
A vendor patch is available. Please see the references for more information.
References
Apache CouchDB CVE-2012-5649 Remote Code Execution Vulnerability
References:
References:
- Apache CouchDB Homepage (Apache Software Foundation)