CVE-2013-4984: OS Command Injection
The closeconnections function in /opt/cma/bin/clearkeys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4984?
CVE-2013-4984 has a moderate severity rating due to the potential for local users to gain privileges through shell metacharacters.
How do I fix CVE-2013-4984?
To fix CVE-2013-4984, upgrade the Sophos Web Appliance to version 3.7.9.1 or later for versions below 3.8.
Which versions of Sophos Web Appliance are affected by CVE-2013-4984?
CVE-2013-4984 affects Sophos Web Appliance versions prior to 3.7.9.1 and 3.8 before 3.8.1.1.
What types of attacks can exploit CVE-2013-4984?
CVE-2013-4984 can be exploited by local users through crafted input that includes shell metacharacters.
Is there a workaround for CVE-2013-4984 if I cannot immediately upgrade?
There are no recommended workarounds for CVE-2013-4984, so it is advised to prioritize an upgrade as soon as possible.