REDHAT-BUG-969296: Medium severity zenoss vulnerability
Thomas Pollet (thomas.pollet) reports:
Also, the rrdtool python module crashes on format string exploit $ python -c "import rrdtool rrdtool.graph('/tmp/out.png','-f','%n%n')" Segmentation fault
this module is used by zenoss to create graphs (zenoss users are able to pass arguments to rrdtool).
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-969296?
The severity of REDHAT-BUG-969296 is high due to the potential for a format string exploit that leads to a segmentation fault.
How do I fix REDHAT-BUG-969296?
To fix REDHAT-BUG-969296, ensure you are using the latest version of the rrdtool and Zenoss software that addresses this vulnerability.
What is affected by REDHAT-BUG-969296?
The rrdtool Python module and Zenoss are affected by REDHAT-BUG-969296, which can lead to crashes when exploited.
Can REDHAT-BUG-969296 lead to data loss?
Yes, if exploited, REDHAT-BUG-969296 might cause data loss due to unexpected crashes in applications using the rrdtool module.
Is REDHAT-BUG-969296 being actively addressed?
Yes, the development teams for both rrdtool and Zenoss are actively working on patches to resolve REDHAT-BUG-969296.