9
CVE-2012-3366
- EPSS 3.82%
- Veröffentlicht 03.07.2012 16:40:35
- Zuletzt bearbeitet 16.06.2026 23:43:05
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.82% | 0.887 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
http://permalink.gmane.org/gmane.comp.sysutils.bcfg2.devel/4539
http://secunia.com/advisories/49629
http://secunia.com/advisories/49690
http://www.debian.org/security/2012/dsa-2503
http://www.securityfocus.com/bid/54217
https://exchange.xforce.ibmcloud.com/vulnerabilities/76616
https://github.com/Bcfg2/bcfg2/commit/a524967e8d5c4c22e49cd619aed20c87a316c0be