CVE-2012-3448: High severity Ganglia Ganglia-web vulnerability
Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown attack vectors.
Other sources
Upstream has released Ganglia Web 3.5.1 [1] which includes a fix for a security flaw going back to 3.1.7 and possibly earlier versions. This flaw can lead to the arbitrary execution of scripts with the privileges of the web user (apache or nobody), which could possibly lead to other compromises or data exposure. This flaw has been fixed in upstream 3.5.1. No further information is currently available regarding the flaw or a patch.
[1] http://ganglia.info/?p=549
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3448?
CVE-2012-3448 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2012-3448?
To fix CVE-2012-3448, upgrade to Ganglia Web version 3.5.1 or later.
Which versions of Ganglia Web are affected by CVE-2012-3448?
CVE-2012-3448 affects Ganglia Web versions prior to 3.5.1, including versions from 3.1.7 and earlier.
Can CVE-2012-3448 be exploited remotely?
Yes, CVE-2012-3448 can be exploited remotely, allowing attackers to execute arbitrary PHP code.
Is there an official patch for CVE-2012-3448?
Yes, an official patch is included in Ganglia Web version 3.5.1 and later.