CVE-2013-1057: Input Validation
Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse importpxefiles configuration file in the current working directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1057?
CVE-2013-1057 is categorized as a low to medium severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2013-1057?
To fix CVE-2013-1057, upgrade to a fixed version of MAAS or ensure that the import_pxe_files configuration files are sourced from a trusted directory.
Which versions of MAAS are affected by CVE-2013-1057?
CVE-2013-1057 affects MAAS versions up to and including 12.04.4.
Can local users exploit CVE-2013-1057?
Yes, local users can exploit CVE-2013-1057 to execute arbitrary code with the privileges of the MAAS application.
How does CVE-2013-1057 work?
CVE-2013-1057 exploits an untrusted search path that allows the execution of malicious configuration files in the current working directory.