PlRPC Pre Autentication CVE-2013-7284 Arbitrary Code Execution Vulnerability
BID:66491
Info
PlRPC Pre Autentication CVE-2013-7284 Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 66491 |
| Class: | Design Error |
| CVE: |
CVE-2013-7284 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2013 12:00AM |
| Updated: | Nov 14 2013 12:00AM |
| Credit: | Ratul Gupta |
| Vulnerable: |
PlRPC PlRPC 0.202.0-r1 Gentoo Linux |
| Not Vulnerable: | |
Discussion
PlRPC Pre Autentication CVE-2013-7284 Arbitrary Code Execution Vulnerability
PlRPC is prone to an arbitrary code-execution vulnerability.
An attacker can leverage this issue to execute arbitrary code within the context of the application.
PlRPC is prone to an arbitrary code-execution vulnerability.
An attacker can leverage this issue to execute arbitrary code within the context of the application.
Exploit / POC
PlRPC Pre Autentication CVE-2013-7284 Arbitrary Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PlRPC Pre Autentication CVE-2013-7284 Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
PlRPC Pre Autentication CVE-2013-7284 Arbitrary Code Execution Vulnerability
References:
References:
- Bug 1051108 - (CVE-2013-7284) CVE-2013-7284 perl-PlRPC: pre-auth remote code exe (Red Hat Bugzilla)
- PlRPC Module Homepage (CPAN)