CVE-2009-4261
ganeti - arbitrary command execution
EPSS 3.3%
描述
Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary programs via a crafted external script name supplied through the HTTP remote API (RAPI) and allow (2) local users to execute arbitrary programs and gain privileges via a crafted external script name supplied through a gnt-* command, related to "path sanitization errors."
如何修補 CVE-2009-4261
要修補 CVE-2009-4261,請將受影響套件升級到下列已修補版本。
- Debian/ganeti—升級至 2.0.5-1 或更新版本
- —升級至 1.2.6-3+lenny2 或更新版本
CVE-2009-4261 正在被利用嗎?
低 — EPSS 為 3.3%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.0.5-1
- from 0, < 1.2.6-3+lenny2