Home page logo
/

bugtraq logo Bugtraq mailing list archives

[SECURITY] [DSA 2503-1] bcfg2 security update
From: Florian Weimer <fw () deneb enyo de>
Date: Thu, 28 Jun 2012 19:49:45 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-2503-1                   security () debian org
http://www.debian.org/security/                            Florian Weimer
June 28, 2012                          http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : bcfg2
Vulnerability  : shell command injection
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2012-3366
Debian Bug     : 679272

It was discovered that malicious clients can trick the server
component of the Bcfg2 configuration management system to execute
commands with root privileges.

For the stable distribution (squeeze), this problem has been fixed in
version 1.0.1-3+squeeze2.

For the unstable distribution (sid), this problem has been fixed in
version 1.2.2-2.

We recommend that you upgrade your bcfg2 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce () lists debian org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iQEcBAEBAgAGBQJP7Jr1AAoJEL97/wQC1SS+qs4IAK14MzCHurmbqJQQYTIsQDdD
uNmFMEWoorDcLIV+2wXQ4atVFreVIFJ+Bbugx170h/SYNNALxjUmoEWzfWaeMMIE
Xe9WpOTLIIuGaOj2l/Sg/tfyLJ4QVkKyKzwBZqd3SQT0IRA3q8Pe5J7Wq8uuhYXm
2INe4AUbVmlw4F1eCMgw66ka8cyXLfQN23PQ7bWwRK4H0hsztaPKKIOei5Y6HAvT
gl4ZMJB/6uOQcgXTRYHdiVTbnjPpvL9FfE/TNl7eGOqpJUKl6F6F6NEj3rG90ZOr
wGL4UH/CUKUKWn/aLeJffwWky8hmHHOeeb05JQFh2/H+o3+vELegWL3zGDrHNC8=
=9CIk
-----END PGP SIGNATURE-----


  By Date           By Thread  

Current thread:
  • [SECURITY] [DSA 2503-1] bcfg2 security update Florian Weimer (Jun 28)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault