|
Cfengine Remotely Exploitable Buffer Overflow
|
|
Secunia Advisory:
|
SA9855
|
|
|
Release Date:
|
2003-09-26
|
|
Popularity:
|
6,365 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
DoS System access
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Cfengine 2.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: A vulnerability has been identified in Cfengine allowing malicious people to execute arbitrary code on the master server.
The problem is that it is possible to overflow the receive buffer by sending more than 4096 bytes to port 5308/tcp. This could be exploited to execute arbitrary code.
The vulnerability affects versions 2.x prior to version 2.0.8.
Solution: Version 2.0.8 is not vulnerable.
http://www.cfengine.org/mirrors.html
Filter access at your perimeter and on the master server allowing only trusted IP adresses to connect.
Provided and/or discovered by: Nick Cleaton
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|