REDHAT-BUG-736279: High severity Bcfg2 bcfg2 configuration management server vulnerability
It was found that bcfg2 configuration management server did not properly escape shell commands data, provided by remote bcfg2 client, prior their execution, when the SSHbase plug-in was enabled. A remote attacker, able to control the client bcfg2 machine, could use this flaw to escalate their privileges (execute arbitrary code with the privileges of the user running the bcfg2 server).
References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=640028 [2] http://www.openwall.com/lists/oss-security/2011/09/01/1 (CVE request) [3] http://www.openwall.com/lists/oss-security/2011/09/06/1 (CVE assignment)
Upstream patches: [4] https://github.com/solj/bcfg2/commit/f4a35efec1b6a1e54d61cf1b8bfc83dd1d89eef7 [5] https://github.com/solj/bcfg2/commit/46795ae451ca6ede55a0edeb726978aef4684b53
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-736279?
The severity of REDHAT-BUG-736279 is considered high due to the potential for remote code execution and privilege escalation.
How do I fix REDHAT-BUG-736279?
To fix REDHAT-BUG-736279, update your bcfg2 configuration management server to the latest version that addresses this vulnerability.
What systems are affected by REDHAT-BUG-736279?
REDHAT-BUG-736279 affects the bcfg2 configuration management server when the SSHbase plug-in is enabled.
Who can exploit REDHAT-BUG-736279?
A remote attacker with control over a bcfg2 client machine can exploit REDHAT-BUG-736279.
What types of attacks can REDHAT-BUG-736279 enable?
REDHAT-BUG-736279 can enable an attacker to perform privilege escalation due to improper shell command data handling.