First published: Mon Oct 18 2010(Updated: )
Cobbler is a network install server. Cobbler supports PXE, virtualized<br>installs, and re-installing existing Linux machines. Cheetah is a template<br>engine used by Cobbler to process kickstart files.<br>A code injection flaw was found in the way Cobbler processed templates for<br>kickstart files. A remote, authenticated user, that has the Configuration<br>Administrator role privilege, could use this flaw to create a<br>specially-crafted kickstart template file containing embedded Python code<br>that could, when processed by Cheetah, execute arbitrary code with root<br>privileges on the Red Hat Network Satellite Server. (CVE-2010-2235)<br>Red Hat would like to thank Doug Knight of the University of Alaska for<br>reporting this issue.<br>Users of Red Hat Network Satellite Server 5.3 are advised to upgrade to<br>this updated cobbler package, which contains backported patches to correct<br>this issue. Red Hat Network Satellite Server must be restarted<br>("/usr/sbin/rhn-satellite restart") for this update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cobbler | <1.6.6-15.el5 | 1.6.6-15.el5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2010:0775 is classified as important.
To fix RHSA-2010:0775, update the Cobbler package to version 1.6.6-15.el5 or later.
RHSA-2010:0775 addresses a code injection flaw in the way Cobbler processes templates.
The affected software for RHSA-2010:0775 is the Cobbler package version 1.6.6-15.el5.
Cobbler is a network install server that supports PXE and virtualized installations for Linux machines.