Vulnerability Description
The doHotCopy subroutine in socket-server.pl in Zmanda Recovery Manager (ZRM) for MySQL 2.x before 2.1.1 allows remote attackers to execute arbitrary commands via vectors involving a crafted $MYSQL_BINPATH variable.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zmanda | Zrm For My Sql | 2.1 |
Related Weaknesses (CWE)
References
- http://forums.zmanda.com/showthread.php?p=8068
- http://secunia.com/advisories/36424Vendor Advisory
- http://secunia.com/advisories/36429Vendor Advisory
- http://twitter.com/elegerov/statuses/3518763099
- http://twitter.com/elegerov/statuses/3547652507
- http://www.intevydis.com/blog/?p=51
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52977
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52978
- http://forums.zmanda.com/showthread.php?p=8068
- http://secunia.com/advisories/36424Vendor Advisory
- http://secunia.com/advisories/36429Vendor Advisory
- http://twitter.com/elegerov/statuses/3518763099
- http://twitter.com/elegerov/statuses/3547652507
- http://www.intevydis.com/blog/?p=51
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52977
FAQ
What is CVE-2009-3102?
CVE-2009-3102 is a vulnerability with a CVSS score of 10.0 (HIGH). The doHotCopy subroutine in socket-server.pl in Zmanda Recovery Manager (ZRM) for MySQL 2.x before 2.1.1 allows remote attackers to execute arbitrary commands via vectors involving a crafted $MYSQL_BI...
How severe is CVE-2009-3102?
CVE-2009-3102 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-3102?
Check the references section above for vendor advisories and patch information. Affected products include: Zmanda Zrm For My Sql.