CVE-2008-0003: Buffer Overflow
Stack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to use PAM and without PEGASUSUSEPAMSTANDALONEPROC defined, might allow remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2007-5360.
Other sources
Whilst investigating a VMWare reported buffer overflow vulnerability (bug #426568) in the PAM authentication code in the OpenPegasus CIM management server that didn't affect Red Hat packages, I found another one that did.
This vulnerability can be exploited remotely and results in arbitrary code execution with the privileges of the cimserver process. Note that we do ship with a default SELinux policy for this package.
Current embargo is unset. Likely to be 2nd week of Jan 2008.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0003?
CVE-2008-0003 has been assigned a high severity rating due to the potential for remote code execution.
How do I fix CVE-2008-0003?
To mitigate CVE-2008-0003, upgrade to the patched versions of the tog-pegasus package as recommended by your vendor.
Which software is affected by CVE-2008-0003?
CVE-2008-0003 affects the tog-pegasus package on certain versions of Red Hat Enterprise Linux.
Can CVE-2008-0003 allow unauthorized access?
Yes, CVE-2008-0003 may allow remote attackers to gain unauthorized access through a buffer overflow vulnerability.
Is CVE-2008-0003 specific to any operating system version?
CVE-2008-0003 impacts specific versions of Red Hat Enterprise Linux and OpenPegasus Management server when they are configured improperly.