REDHAT-BUG-1121497: High severity Snoopy Snoopy library vulnerability
CVE-2008-4796 describes a command execution flaw in the Snoopy library. A similar fix exists for headers:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.27
The header fix has been assigned CVE-2008-7313 (as an incomplete fix for CVE-2008-4796).
It was later reported that the CVE-2008-4796 fix was incomplete and command execution was still possible:
http://mstrokin.com/sec/feed2js-magpierss-0day-vulnerability-not-really-it-is-actually-cve-2005-3330-cve-2008-4796/
And fixed with the following:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.28
This has been assigned CVE-2014-5008 (as an incomplete fix for CVE-2008-4796).
However, the CVE-2014-5008 fix was also incomplete:
https://github.com/cogdog/feed2js/pull/12#issuecomment-48283706
This was fixed with the following:
http://snoopy.cvs.sourceforge.net/viewvc/snoopy/Snoopy/Snoopy.class.php?view=log#rev1.29
And assigned CVE-2014-5009 (as an incomplete fix for CVE-2014-5008).
References:
http://www.openwall.com/lists/oss-security/2014/07/09/11
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1121497?
The severity of REDHAT-BUG-1121497 is categorized as high due to the potential for command execution vulnerabilities.
How do I fix REDHAT-BUG-1121497?
To fix REDHAT-BUG-1121497, update the Snoopy library to the latest version that contains the security patch.
What vulnerability does REDHAT-BUG-1121497 address?
REDHAT-BUG-1121497 addresses a command execution flaw in the Snoopy library as documented in CVE-2008-4796.
Which versions of Snoopy library are affected by REDHAT-BUG-1121497?
All versions of the Snoopy library prior to the patch that addresses the flaw in REDHAT-BUG-1121497 are affected.
Is REDHAT-BUG-1121497 associated with any known exploits?
Yes, REDHAT-BUG-1121497 is associated with known exploits that can leverage command execution vulnerabilities.