First published: Mon Jan 07 2008(Updated: )
The tog-pegasus packages provide OpenPegasus Web-Based Enterprise<br>Management (WBEM) services. WBEM is a platform and resource independent<br>DMTF standard that defines a common information model, and communication<br>protocol for monitoring and controlling resources.<br>During a security audit, a stack buffer overflow flaw was found in the PAM<br>authentication code in the OpenPegasus CIM management server. An<br>unauthenticated remote user could trigger this flaw and potentially execute<br>arbitrary code with root privileges. (CVE-2008-0003)<br>Note that the tog-pegasus packages are not installed by default on Red Hat<br>Enterprise Linux. The Red Hat Security Response Team believes that it would<br>be hard to remotely exploit this issue to execute arbitrary code, due to<br>the default SELinux targeted policy on Red Hat Enterprise Linux 4 and 5,<br>and the SELinux memory protection tests enabled by default on Red Hat<br>Enterprise Linux 5.<br>Users of tog-pegasus should upgrade to these updated packages, which<br>contain a backported patch to resolve this issue. After installing the<br>updated packages the tog-pegasus service should be restarted.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/tog-pegasus | <2.6.1-2.el5_1.1 | 2.6.1-2.el5_1.1 |
redhat/tog-pegasus | <2.6.1-2.el5_1.1 | 2.6.1-2.el5_1.1 |
redhat/tog-pegasus-devel | <2.6.1-2.el5_1.1 | 2.6.1-2.el5_1.1 |
redhat/tog-pegasus-devel | <2.6.1-2.el5_1.1 | 2.6.1-2.el5_1.1 |
redhat/tog-pegasus | <2.5.1-5.el4_6.1 | 2.5.1-5.el4_6.1 |
redhat/tog-pegasus | <2.5.1-5.el4_6.1 | 2.5.1-5.el4_6.1 |
redhat/tog-pegasus-devel | <2.5.1-5.el4_6.1 | 2.5.1-5.el4_6.1 |
redhat/tog-pegasus-test | <2.5.1-5.el4_6.1 | 2.5.1-5.el4_6.1 |
redhat/tog-pegasus-devel | <2.5.1-5.el4_6.1 | 2.5.1-5.el4_6.1 |
redhat/tog-pegasus-test | <2.5.1-5.el4_6.1 | 2.5.1-5.el4_6.1 |
redhat/tog-pegasus | <2.5.1-2.el4_5.1 | 2.5.1-2.el4_5.1 |
redhat/tog-pegasus | <2.5.1-2.el4_5.1 | 2.5.1-2.el4_5.1 |
redhat/tog-pegasus-devel | <2.5.1-2.el4_5.1 | 2.5.1-2.el4_5.1 |
redhat/tog-pegasus-test | <2.5.1-2.el4_5.1 | 2.5.1-2.el4_5.1 |
redhat/tog-pegasus-devel | <2.5.1-2.el4_5.1 | 2.5.1-2.el4_5.1 |
redhat/tog-pegasus-test | <2.5.1-2.el4_5.1 | 2.5.1-2.el4_5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.