6.5

CVE-2011-0730

Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eucalyptus ≫ Eucalyptus SwEdition enterprise Version < 2.0.2
Eucalyptus ≫ Eucalyptus Version < 2.0.3
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 10.10
Canonical ≫ Ubuntu Linux Version 11.04
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.17% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://launchpadlibrarian.net/72472626/eucalyptus_2.0.1%2Bbzr1256-0ubuntu5_2.0.1%2Bbzr1256-0ubuntu6.diff.gz
Patch
Third Party Advisory
http://open.eucalyptus.com/wiki/esa-02
Vendor Advisory
http://secunia.com/advisories/44705
Third Party Advisory
http://www.securityfocus.com/bid/48000
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-1137-1
Third Party Advisory
https://bugs.launchpad.net/bugs/746101
Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/67670
Third Party Advisory
VDB Entry
https://launchpad.net/ubuntu/+source/eucalyptus/+changelog
Patch
Third Party Advisory