Sophos Web Protection Appliance CVE-2013-4984 Local Command Injection Vulnerability
BID:62265
Info
Sophos Web Protection Appliance CVE-2013-4984 Local Command Injection Vulnerability
| Bugtraq ID: | 62265 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4984 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 06 2013 12:00AM |
| Updated: | Sep 18 2013 12:11AM |
| Credit: | Francisco Falcon from Core Exploit Writers Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Sophos Web Protection Appliance CVE-2013-4984 Local Command Injection Vulnerability
Sophos Web Protection Appliance is prone to a local command-injection vulnerability.
A local attacker may exploit this to execute arbitrary commands with root privileges. Successful exploits will result in the complete compromise of affected computers.
Versions prior to Web Protection Appliance 3.7.9.1 and 3.8.1.1 are vulnerable.
Sophos Web Protection Appliance is prone to a local command-injection vulnerability.
A local attacker may exploit this to execute arbitrary commands with root privileges. Successful exploits will result in the complete compromise of affected computers.
Versions prior to Web Protection Appliance 3.7.9.1 and 3.8.1.1 are vulnerable.
Exploit / POC
Sophos Web Protection Appliance CVE-2013-4984 Local Command Injection Vulnerability
An attacker can exploit this issue using standard commands.
The following exploit code is available.
An attacker can exploit this issue using standard commands.
The following exploit code is available.
Solution / Fix
Sophos Web Protection Appliance CVE-2013-4984 Local Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Sophos Web Protection Appliance CVE-2013-4984 Local Command Injection Vulnerability
References:
References: