Vulnerability Description
Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary programs via a crafted external script name supplied through the HTTP remote API (RAPI) and allow (2) local users to execute arbitrary programs and gain privileges via a crafted external script name supplied through a gnt-* command, related to "path sanitization errors."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Roman Marxer | Ganeti | 1.2.4 |
Related Weaknesses (CWE)
References
- http://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=NEWS%3Bh=34b46426eca82c351e
- http://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=lib/constants.py%3Bh=813025
- http://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=lib/utils.py%3Bh=bcd8e107bb
- http://git.ganeti.org/?p=ganeti.git%3Ba=commit%3Bh=f95c81bf21c177f7e6a2c53ea0613
- http://groups.google.com/group/ganeti/browse_thread/thread/cbce23d89103a8d2Patch
- http://secunia.com/advisories/37849Vendor Advisory
- http://www.ocert.org/advisories/ocert-2009-019.html
- http://www.openwall.com/lists/oss-security/2009/12/17/5
- http://www.securityfocus.com/archive/1/508535/100/0/threaded
- http://www.vupen.com/english/advisories/2009/3599Vendor Advisory
- http://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=NEWS%3Bh=34b46426eca82c351e
- http://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=lib/constants.py%3Bh=813025
- http://git.ganeti.org/?p=ganeti.git%3Ba=blobdiff%3Bf=lib/utils.py%3Bh=bcd8e107bb
- http://git.ganeti.org/?p=ganeti.git%3Ba=commit%3Bh=f95c81bf21c177f7e6a2c53ea0613
- http://groups.google.com/group/ganeti/browse_thread/thread/cbce23d89103a8d2Patch
FAQ
What is CVE-2009-4261?
CVE-2009-4261 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary ...
How severe is CVE-2009-4261?
CVE-2009-4261 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4261?
Check the references section above for vendor advisories and patch information. Affected products include: Roman Marxer Ganeti.