CVE-2011-3211: Input Validation
It was found that bcfg2 configuration management server did not properly escape shell commands data, provided by remote bcfg2 client, prior their execution, when the SSHbase plug-in was enabled. A remote attacker, able to control the client bcfg2 machine, could use this flaw to escalate their privileges (execute arbitrary code with the privileges of the user running the bcfg2 server).
References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=640028 [2] http://www.openwall.com/lists/oss-security/2011/09/01/1 (CVE request) [3] http://www.openwall.com/lists/oss-security/2011/09/06/1 (CVE assignment)
Upstream patches: [4] https://github.com/solj/bcfg2/commit/f4a35efec1b6a1e54d61cf1b8bfc83dd1d89eef7 [5] https://github.com/solj/bcfg2/commit/46795ae451ca6ede55a0edeb726978aef4684b53
Other sources
The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, allows remote attackers to execute arbitrary commands via shell metacharacters in data received from a client.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3211?
CVE-2011-3211 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2011-3211?
To fix CVE-2011-3211, update your bcfg2 installation to a version that includes the relevant security patches.
What software versions are affected by CVE-2011-3211?
CVE-2011-3211 affects bcfg2 versions up to and including 1.1.2, as well as various earlier versions.
Can CVE-2011-3211 be exploited remotely?
Yes, CVE-2011-3211 can be exploited remotely if an attacker has control over the client bcfg2 system.
What type of attacks can CVE-2011-3211 enable?
CVE-2011-3211 can enable attackers to execute arbitrary shell commands on the server, leading to potential data compromise.